<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://nvd.nist.gov/feeds/cve/1.2" nvd_xml_version="1.2" pub_date="2013-06-17" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd">
  <entry type="CVE" severity="Medium" seq="2007-0001" published="2007-03-02" name="CVE-2007-0001" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">The file watch implementation in the audit subsystem (auditctl -w) in the Red Hat Enterprise Linux (RHEL) 4 kernel 2.6.9 allows local users to cause a denial of service (kernel panic) by replacing a watched file, which does not cause the watch on the old inode to be dropped.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that the attacker previously created a watch for a file.</impact>
    </impacts>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0085.html" source="REDHAT" patch="1" adv="1">RHSA-2007:0085</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=223129" source="MISC" patch="1">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=223129</ref>
      <ref url="http://www.securitytracker.com/id?1017705" source="SECTRACK">1017705</ref>
      <ref url="http://www.securityfocus.com/bid/22737" source="BID">22737</ref>
      <ref url="http://secunia.com/advisories/24300" source="SECUNIA" adv="1">24300</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9560" source="OVAL">oval:org.mitre.oval:def:9560</ref>
      <ref url="http://osvdb.org/33031" source="OSVDB">33031</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":linux_kernel_2.6.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0002" published="2007-03-16" name="CVE-2007-0002" modified="2011-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allow user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted WordPerfect file in which values to loop counters are not properly handled in the (1) WP3TablesGroup::_readContents and (2) WP5DefinitionGroup_DefineTablesSubGroup::WP5DefinitionGroup_DefineTablesSubGroup functions.  NOTE: the integer overflow has been split into CVE-2007-1466.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability has been addressed by the vendor through a product update: http://sourceforge.net/projects/libwpd/ </sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1339" source="VUPEN" adv="1">ADV-2007-1339</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1032" source="VUPEN" adv="1">ADV-2007-1032</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0976" source="VUPEN" adv="1">ADV-2007-0976</ref>
      <ref url="http://www.ubuntu.com/usn/usn-437-1" source="UBUNTU">USN-437-1</ref>
      <ref url="http://www.securitytracker.com/id?1017789" source="SECTRACK">1017789</ref>
      <ref url="http://www.securityfocus.com/bid/23006" source="BID">23006</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463033/100/0/threaded" source="BUGTRAQ">20070316 rPSA-2007-0057-1 libwpd</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0055.html" source="REDHAT" adv="1">RHSA-2007:0055</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:064" source="MANDRIVA">MDKSA-2007:064</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:063" source="MANDRIVA">MDKSA-2007:063</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200704-12.xml" source="GENTOO">GLSA-200704-12</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1270" source="DEBIAN">DSA-1270</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1268" source="DEBIAN">DSA-1268</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102863-1" source="SUNALERT">102863</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=494122" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=494122</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.399659" source="SLACKWARE">SSA-2007-085-02</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200704-07.xml" source="GENTOO">GLSA-200704-07</ref>
      <ref url="http://secunia.com/advisories/24906" source="SECUNIA" adv="1">24906</ref>
      <ref url="http://secunia.com/advisories/24856" source="SECUNIA" adv="1">24856</ref>
      <ref url="http://secunia.com/advisories/24794" source="SECUNIA" adv="1">24794</ref>
      <ref url="http://secunia.com/advisories/24613" source="SECUNIA" adv="1">24613</ref>
      <ref url="http://secunia.com/advisories/24593" source="SECUNIA" adv="1">24593</ref>
      <ref url="http://secunia.com/advisories/24591" source="SECUNIA" adv="1">24591</ref>
      <ref url="http://secunia.com/advisories/24588" source="SECUNIA" adv="1">24588</ref>
      <ref url="http://secunia.com/advisories/24581" source="SECUNIA" adv="1">24581</ref>
      <ref url="http://secunia.com/advisories/24580" source="SECUNIA" adv="1">24580</ref>
      <ref url="http://secunia.com/advisories/24573" source="SECUNIA" adv="1">24573</ref>
      <ref url="http://secunia.com/advisories/24572" source="SECUNIA" adv="1">24572</ref>
      <ref url="http://secunia.com/advisories/24557" source="SECUNIA" adv="1">24557</ref>
      <ref url="http://secunia.com/advisories/24507" source="SECUNIA" adv="1">24507</ref>
      <ref url="http://secunia.com/advisories/24465" source="SECUNIA" adv="1">24465</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11535" source="OVAL">oval:org.mitre.oval:def:11535</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0007.html" source="SUSE">SUSE-SA:2007:023</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=490" source="IDEFENSE">20070316 Multiple Vendor libwpd Multiple Buffer Overflow Vulnerabilities</ref>
      <ref url="http://fedoranews.org/cms/node/2805" source="FEDORA">FEDORA-2007-350</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libwpd" name="libwpd_library">
        <vers num="0.8.2"/>
        <vers num="0.8.6"/>
        <vers num="0.8.7"/>
        <vers prev="1" num="0.8.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0003" published="2007-01-23" name="CVE-2007-0003" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">pam_unix.so in Linux-PAM 0.99.7.0 allows context-dependent attackers to log into accounts whose password hash, as stored in /etc/passwd or /etc/shadow, has only two characters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/pam-list/2007-January/msg00017.html" source="MLIST" adv="1">[pam-list] 20070123 Linux-PAM 0.99.7.1 released</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0323" source="VUPEN">ADV-2007-0323</ref>
      <ref url="http://www.redhat.com/archives/fedora-devel-list/2007-January/msg01277.html" source="MLIST" adv="1">[fedora-devel-list] 20070122 Re: rawhide report: 20070120 changes</ref>
      <ref url="http://www.redhat.com/archives/fedora-devel-list/2007-January/msg01271.html" source="MLIST" adv="1">[fedora-devel-list] 20070122 Re: rawhide report: 20070120 changes</ref>
      <ref url="http://osvdb.org/32017" source="OSVDB">32017</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31739" source="XF">linuxpam-pamunix-security-bypass(31739)</ref>
      <ref url="http://www.securityfocus.com/bid/22204" source="BID">22204</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_3_sr.html" source="SUSE">SUSE-SR:2007:003</ref>
      <ref url="http://secunia.com/advisories/23858" source="SECUNIA">23858</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andrew_morgan" name="linux_pam">
        <vers num="0.99.7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0004" published="2007-09-18" name="CVE-2007-0004" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">The NFS client implementation in the kernel in Red Hat Enterprise Linux (RHEL) 3, when a filesystem is mounted with the noacl option, checks permissions for the open system call via vfs_permission (mode bits) data rather than an NFS ACCESS call to the server, which allows local client processes to obtain a false success status from open calls that the server would deny, and possibly obtain sensitive information about file permissions on the server, as demonstrated in a root_squash environment.  NOTE: it is uncertain whether any scenarios involving this issue cross privilege boundaries.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=199715" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=199715</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0005" published="2007-03-09" name="CVE-2007-0005" modified="2012-03-19" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Multiple buffer overflows in the (1) read and (2) write handlers in the Omnikey CardMan 4040 driver in the Linux kernel before 2.6.21-rc3 allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.21-rc3" source="CONFIRM" patch="1" adv="1">http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.21-rc3</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1035" source="CONFIRM">https://issues.rpath.com/browse/RPL-1035</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32880" source="XF">kernel-cardman4040drivers-bo(32880)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0872" source="VUPEN" adv="1">ADV-2007-0872</ref>
      <ref url="http://www.ubuntu.com/usn/usn-489-1" source="UBUNTU">USN-489-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-486-1" source="UBUNTU">USN-486-1</ref>
      <ref url="http://www.securityfocus.com/bid/22870" source="BID">22870</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462300/100/0/threaded" source="BUGTRAQ">20070309 Buffer Overflow in Linux Drivers for Omnikey CardMan 4040 (CVE-2007-0005)</ref>
      <ref url="http://www.securityfocus.com/archive/1/471457" source="BUGTRAQ">20070615 rPSA-2007-0124-1 kernel xen</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0099.html" source="REDHAT" adv="1">RHSA-2007:0099</ref>
      <ref url="http://www.osvdb.org/33023" source="OSVDB">33023</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:078" source="MANDRIVA">MDKSA-2007:078</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1286" source="DEBIAN">DSA-1286</ref>
      <ref url="http://secunia.com/advisories/26139" source="SECUNIA" adv="1">26139</ref>
      <ref url="http://secunia.com/advisories/26133" source="SECUNIA" adv="1">26133</ref>
      <ref url="http://secunia.com/advisories/25691" source="SECUNIA" adv="1">25691</ref>
      <ref url="http://secunia.com/advisories/25078" source="SECUNIA" adv="1">25078</ref>
      <ref url="http://secunia.com/advisories/24901" source="SECUNIA" adv="1">24901</ref>
      <ref url="http://secunia.com/advisories/24777" source="SECUNIA" adv="1">24777</ref>
      <ref url="http://secunia.com/advisories/24518" source="SECUNIA" adv="1">24518</ref>
      <ref url="http://secunia.com/advisories/24436" source="SECUNIA" adv="1">24436</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11238" source="OVAL">oval:org.mitre.oval:def:11238</ref>
      <ref url="http://fedoranews.org/cms/node/2788" source="FEDORA">FEDORA-2007-336</ref>
      <ref url="http://fedoranews.org/cms/node/2787" source="FEDORA">FEDORA-2007-335</ref>
    </refs>
    <vuln_soft>
      <prod vendor="omnikey.aaitg" name="omnikey_cardman_4040">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0006" published="2007-02-06" name="CVE-2007-0006" modified="2010-09-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">The key serial number collision avoidance code in the key_alloc_serial function in Linux kernel 2.6.9 up to 2.6.20 allows local users to cause a denial of service (crash) via vectors that trigger a null dereference, as originally reported as "spinlock CPU recursion."</descript>
    </desc>
    <impacts>
      <impact source="nvd">The scheme for selecting serial numbers was changed from incrementing a counter to random number selection, increasing the likelihood of a serial number collision.</impact>
    </impacts>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://issues.rpath.com/browse/RPL-1097" source="CONFIRM">https://issues.rpath.com/browse/RPL-1097</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=227495" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=227495</ref>
      <ref url="http://www.ubuntu.com/usn/usn-451-1" source="UBUNTU">USN-451-1</ref>
      <ref url="http://www.securityfocus.com/bid/22539" source="BID">22539</ref>
      <ref url="http://www.securityfocus.com/archive/1/471457" source="BUGTRAQ">20070615 rPSA-2007-0124-1 kernel xen</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0099.html" source="REDHAT">RHSA-2007:0099</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0085.html" source="REDHAT">RHSA-2007:0085</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_21_kernel.html" source="SUSE">SUSE-SA:2007:021</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:060" source="MANDRIVA">MDKSA-2007:060</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:047" source="MANDRIVA">MDKSA-2007:047</ref>
      <ref url="http://secunia.com/advisories/25691" source="SECUNIA" adv="1">25691</ref>
      <ref url="http://secunia.com/advisories/24752" source="SECUNIA" adv="1">24752</ref>
      <ref url="http://secunia.com/advisories/24547" source="SECUNIA" adv="1">24547</ref>
      <ref url="http://secunia.com/advisories/24482" source="SECUNIA" adv="1">24482</ref>
      <ref url="http://secunia.com/advisories/24429" source="SECUNIA" adv="1">24429</ref>
      <ref url="http://secunia.com/advisories/24300" source="SECUNIA" adv="1">24300</ref>
      <ref url="http://secunia.com/advisories/24259" source="SECUNIA" adv="1">24259</ref>
      <ref url="http://secunia.com/advisories/24109" source="SECUNIA" adv="1">24109</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9829" source="OVAL">oval:org.mitre.oval:def:9829</ref>
      <ref url="http://bugzilla.kernel.org/show_bug.cgi?id=7727" source="CONFIRM">http://bugzilla.kernel.org/show_bug.cgi?id=7727</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.6.20"/>
        <vers num="2.6.9" edition="2.6.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0007" published="2007-02-19" name="CVE-2007-0007" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">gnucash 2.0.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) gnucash.trace, (2) qof.trace, and (3) qof.trace.[PID] temporary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24225" source="SECUNIA" patch="1" adv="1">24225</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=223233" source="CONFIRM" adv="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=223233</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0653" source="VUPEN">ADV-2007-0653</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32558" source="XF">gnucash-symlink(32558)</ref>
      <ref url="http://www.securityfocus.com/bid/22610" source="BID">22610</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:046" source="MANDRIVA">MDKSA-2007:046</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=192&amp;release_id=487446" source="CONFIRM">http://sourceforge.net/project/shownotes.php?group_id=192&amp;release_id=487446</ref>
      <ref url="http://secunia.com/advisories/24317" source="SECUNIA">24317</ref>
      <ref url="http://secunia.com/advisories/24226" source="SECUNIA">24226</ref>
      <ref url="http://fedoranews.org/cms/node/2725" source="FEDORA">FEDORA-2007-256</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnucash" name="gnucash">
        <vers prev="1" num="2.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0008" published="2007-02-26" name="CVE-2007-0008" modified="2011-10-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via a crafted SSLv2 server message containing a public key that is too short to encrypt the "Master Secret", which results in a heap-based overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/377812" source="CERT-VN">VU#377812</ref>
      <ref url="http://www.mozilla.org/security/announce/2007/mfsa2007-06.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/2007/mfsa2007-06.html</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1103" source="CONFIRM">https://issues.rpath.com/browse/RPL-1103</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1081" source="CONFIRM">https://issues.rpath.com/browse/RPL-1081</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=364319" source="MISC" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=364319</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32666" source="XF">nss-mastersecret-bo(32666)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2141" source="VUPEN">ADV-2007-2141</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1165" source="VUPEN">ADV-2007-1165</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0719" source="VUPEN">ADV-2007-0719</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0718" source="VUPEN">ADV-2007-0718</ref>
      <ref url="http://www.ubuntu.com/usn/usn-431-1" source="UBUNTU">USN-431-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-428-1" source="UBUNTU">USN-428-1</ref>
      <ref url="http://www.securitytracker.com/id?1017696" source="SECTRACK">1017696</ref>
      <ref url="http://www.securityfocus.com/bid/22694" source="BID">22694</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded" source="BUGTRAQ">20070303 rPSA-2007-0040-3 firefox thunderbird</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded" source="BUGTRAQ">20070226 rPSA-2007-0040-1 firefox</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0108.html" source="REDHAT">RHSA-2007:0108</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0097.html" source="REDHAT">RHSA-2007:0097</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0079.html" source="REDHAT">RHSA-2007:0079</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0078.html" source="REDHAT">RHSA-2007:0078</ref>
      <ref url="http://www.osvdb.org/32105" source="OSVDB">32105</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:052" source="MANDRIVA">MDKSA-2007:052</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-22.xml" source="GENTOO">GLSA-200703-22</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1336" source="DEBIAN">DSA-1336</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102856-1" source="SUNALERT">102856</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-18.xml" source="GENTOO">GLSA-200703-18</ref>
      <ref url="http://secunia.com/advisories/24703" source="SECUNIA" adv="1">24703</ref>
      <ref url="http://secunia.com/advisories/24650" source="SECUNIA" adv="1">24650</ref>
      <ref url="http://secunia.com/advisories/24562" source="SECUNIA" adv="1">24562</ref>
      <ref url="http://secunia.com/advisories/24522" source="SECUNIA" adv="1">24522</ref>
      <ref url="http://secunia.com/advisories/24410" source="SECUNIA" adv="1">24410</ref>
      <ref url="http://secunia.com/advisories/24395" source="SECUNIA" adv="1">24395</ref>
      <ref url="http://secunia.com/advisories/24389" source="SECUNIA" adv="1">24389</ref>
      <ref url="http://secunia.com/advisories/24384" source="SECUNIA" adv="1">24384</ref>
      <ref url="http://secunia.com/advisories/24343" source="SECUNIA" adv="1">24343</ref>
      <ref url="http://secunia.com/advisories/24333" source="SECUNIA" adv="1">24333</ref>
      <ref url="http://secunia.com/advisories/24328" source="SECUNIA" adv="1">24328</ref>
      <ref url="http://secunia.com/advisories/24320" source="SECUNIA" adv="1">24320</ref>
      <ref url="http://secunia.com/advisories/24293" source="SECUNIA" adv="1">24293</ref>
      <ref url="http://secunia.com/advisories/24290" source="SECUNIA" adv="1">24290</ref>
      <ref url="http://secunia.com/advisories/24287" source="SECUNIA" adv="1">24287</ref>
      <ref url="http://secunia.com/advisories/24277" source="SECUNIA" adv="1">24277</ref>
      <ref url="http://secunia.com/advisories/24253" source="SECUNIA" adv="1">24253</ref>
      <ref url="http://secunia.com/advisories/24252" source="SECUNIA" adv="1">24252</ref>
      <ref url="http://secunia.com/advisories/24238" source="SECUNIA" adv="1">24238</ref>
      <ref url="http://secunia.com/advisories/24205" source="SECUNIA" adv="1">24205</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0077.html" source="REDHAT">RHSA-2007:0077</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10502" source="OVAL">oval:org.mitre.oval:def:10502</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" source="SUSE">SUSE-SA:2007:019</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=482" source="IDEFENSE" adv="1">20070223 Mozilla Network Security Services SSLv2 Client Integer Underflow Vulnerability</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">HPSBUX02153</ref>
      <ref url="http://fedoranews.org/cms/node/2728" source="FEDORA">FEDORA-2007-293</ref>
      <ref url="http://fedoranews.org/cms/node/2713" source="FEDORA">FEDORA-2007-281</ref>
      <ref url="http://fedoranews.org/cms/node/2711" source="FEDORA">FEDORA-2007-279</ref>
      <ref url="http://fedoranews.org/cms/node/2709" source="FEDORA">FEDORA-2007-278</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" source="SGI">20070301-01-P</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" source="SUSE">SUSE-SA:2007:022</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" source="MANDRIVA">MDKSA-2007:050</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102945-1" source="SUNALERT">102945</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" source="SLACKWARE">SSA:2007-066-03</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.363947" source="SLACKWARE">SSA:2007-066-04</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" source="SLACKWARE">SSA:2007-066-05</ref>
      <ref url="http://secunia.com/advisories/25597" source="SECUNIA">25597</ref>
      <ref url="http://secunia.com/advisories/25588" source="SECUNIA">25588</ref>
      <ref url="http://secunia.com/advisories/24457" source="SECUNIA">24457</ref>
      <ref url="http://secunia.com/advisories/24456" source="SECUNIA">24456</ref>
      <ref url="http://secunia.com/advisories/24455" source="SECUNIA">24455</ref>
      <ref url="http://secunia.com/advisories/24406" source="SECUNIA">24406</ref>
      <ref url="http://secunia.com/advisories/24342" source="SECUNIA">24342</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">HPSBUX02153</ref>
      <ref url="http://fedoranews.org/cms/node/2749" source="FEDORA">FEDORA-2007-309</ref>
      <ref url="http://fedoranews.org/cms/node/2747" source="FEDORA">FEDORA-2007-308</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" source="SGI">20070202-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1"/>
        <vers num="0.10"/>
        <vers num="0.10.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.6.1"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.8"/>
        <vers num="0.9" edition="rc"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.4.1"/>
        <vers num="1.5"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers prev="1" num="1.5.0.9"/>
        <vers num="2.0"/>
        <vers num="2.0.0.1"/>
      </prod>
      <prod vendor="mozilla" name="network_security_services">
        <vers num="3.11.2"/>
        <vers num="3.11.3"/>
        <vers num="3.11.4"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers prev="1" num="1.0.7"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers prev="1" num="1.5.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0009" published="2007-02-26" name="CVE-2007-0009" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid "Client Master Key" length values.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/592796" source="CERT-VN">VU#592796</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1103" source="CONFIRM">https://issues.rpath.com/browse/RPL-1103</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1081" source="CONFIRM">https://issues.rpath.com/browse/RPL-1081</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=364323" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=364323</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32663" source="XF">nss-clientmasterkey-bo(32663)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2141" source="VUPEN">ADV-2007-2141</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1165" source="VUPEN">ADV-2007-1165</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0719" source="VUPEN">ADV-2007-0719</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0718" source="VUPEN">ADV-2007-0718</ref>
      <ref url="http://www.ubuntu.com/usn/usn-431-1" source="UBUNTU">USN-431-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-428-1" source="UBUNTU">USN-428-1</ref>
      <ref url="http://www.securitytracker.com/id?1017696" source="SECTRACK">1017696</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded" source="BUGTRAQ">20070303 rPSA-2007-0040-3 firefox thunderbird</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded" source="BUGTRAQ">20070226 rPSA-2007-0040-1 firefox</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0108.html" source="REDHAT">RHSA-2007:0108</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0097.html" source="REDHAT">RHSA-2007:0097</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0079.html" source="REDHAT">RHSA-2007:0079</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0078.html" source="REDHAT">RHSA-2007:0078</ref>
      <ref url="http://www.osvdb.org/32106" source="OSVDB">32106</ref>
      <ref url="http://www.mozilla.org/security/announce/2007/mfsa2007-06.html" source="CONFIRM">http://www.mozilla.org/security/announce/2007/mfsa2007-06.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:052" source="MANDRIVA">MDKSA-2007:052</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" source="MANDRIVA">MDKSA-2007:050</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-22.xml" source="GENTOO">GLSA-200703-22</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1336" source="DEBIAN">DSA-1336</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102945-1" source="SUNALERT">102945</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102856-1" source="SUNALERT">102856</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" source="SLACKWARE">SSA:2007-066-03</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.363947" source="SLACKWARE">SSA:2007-066-04</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" source="SLACKWARE">SSA:2007-066-05</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-18.xml" source="GENTOO">GLSA-200703-18</ref>
      <ref url="http://secunia.com/advisories/24703" source="SECUNIA" adv="1">24703</ref>
      <ref url="http://secunia.com/advisories/24650" source="SECUNIA" adv="1">24650</ref>
      <ref url="http://secunia.com/advisories/24562" source="SECUNIA" adv="1">24562</ref>
      <ref url="http://secunia.com/advisories/24522" source="SECUNIA" adv="1">24522</ref>
      <ref url="http://secunia.com/advisories/24410" source="SECUNIA" adv="1">24410</ref>
      <ref url="http://secunia.com/advisories/24395" source="SECUNIA" adv="1">24395</ref>
      <ref url="http://secunia.com/advisories/24389" source="SECUNIA" adv="1">24389</ref>
      <ref url="http://secunia.com/advisories/24384" source="SECUNIA" adv="1">24384</ref>
      <ref url="http://secunia.com/advisories/24343" source="SECUNIA" adv="1">24343</ref>
      <ref url="http://secunia.com/advisories/24333" source="SECUNIA" adv="1">24333</ref>
      <ref url="http://secunia.com/advisories/24293" source="SECUNIA" adv="1">24293</ref>
      <ref url="http://secunia.com/advisories/24290" source="SECUNIA" adv="1">24290</ref>
      <ref url="http://secunia.com/advisories/24287" source="SECUNIA" adv="1">24287</ref>
      <ref url="http://secunia.com/advisories/24277" source="SECUNIA" adv="1">24277</ref>
      <ref url="http://secunia.com/advisories/24253" source="SECUNIA" adv="1">24253</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0077.html" source="REDHAT">RHSA-2007:0077</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10174" source="OVAL">oval:org.mitre.oval:def:10174</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" source="SUSE">SUSE-SA:2007:019</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=483" source="IDEFENSE">20070223 Mozilla Network Security Services SSLv2 Server Stack Overflow Vulnerability</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">HPSBUX02153</ref>
      <ref url="http://fedoranews.org/cms/node/2749" source="FEDORA">FEDORA-2007-309</ref>
      <ref url="http://fedoranews.org/cms/node/2747" source="FEDORA">FEDORA-2007-308</ref>
      <ref url="http://fedoranews.org/cms/node/2711" source="FEDORA">FEDORA-2007-279</ref>
      <ref url="http://fedoranews.org/cms/node/2709" source="FEDORA">FEDORA-2007-278</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" source="SGI">20070301-01-P</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" source="SGI">20070202-01-P</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" source="SUSE">SUSE-SA:2007:022</ref>
      <ref url="http://secunia.com/advisories/25597" source="SECUNIA">25597</ref>
      <ref url="http://secunia.com/advisories/25588" source="SECUNIA">25588</ref>
      <ref url="http://secunia.com/advisories/24457" source="SECUNIA">24457</ref>
      <ref url="http://secunia.com/advisories/24456" source="SECUNIA">24456</ref>
      <ref url="http://secunia.com/advisories/24455" source="SECUNIA">24455</ref>
      <ref url="http://secunia.com/advisories/24406" source="SECUNIA">24406</ref>
      <ref url="http://secunia.com/advisories/24342" source="SECUNIA">24342</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">HPSBUX02153</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers prev="1" num="1.5.0.9"/>
        <vers prev="1" num="2.0.0.1"/>
      </prod>
      <prod vendor="mozilla" name="network_security_services">
        <vers prev="1" num="3.11.4"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.0.7"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers prev="1" num="1.5.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0010" published="2007-01-24" name="CVE-2007-0010" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The GdkPixbufLoader function in GIMP ToolKit (GTK+) in GTK 2 (gtk2) before 2.4.13 allows context-dependent attackers to cause a denial of service (crash) via a malformed image file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=218932" source="CONFIRM" adv="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=218932</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0331" source="VUPEN">ADV-2007-0331</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0019.html" source="REDHAT" adv="1">RHSA-2007:0019</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10325" source="OVAL">oval:org.mitre.oval:def:10325</ref>
      <ref url="http://osvdb.org/31621" source="OSVDB">31621</ref>
      <ref url="https://issues.rpath.com/browse/RPL-984" source="CONFIRM">https://issues.rpath.com/browse/RPL-984</ref>
      <ref url="http://www.ubuntu.com/usn/usn-415-1" source="UBUNTU">USN-415-1</ref>
      <ref url="http://www.securityfocus.com/bid/22209" source="BID">22209</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_02_sr.html" source="SUSE">SUSE-SR:2007:002</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:039" source="MANDRIVA">MDKSA-2007:039</ref>
      <ref url="http://securitytracker.com/id?1017552" source="SECTRACK">1017552</ref>
      <ref url="http://secunia.com/advisories/24095" source="SECUNIA">24095</ref>
      <ref url="http://secunia.com/advisories/24010" source="SECUNIA">24010</ref>
      <ref url="http://secunia.com/advisories/24006" source="SECUNIA">24006</ref>
      <ref url="http://secunia.com/advisories/23984" source="SECUNIA">23984</ref>
      <ref url="http://secunia.com/advisories/23935" source="SECUNIA">23935</ref>
      <ref url="http://secunia.com/advisories/23933" source="SECUNIA">23933</ref>
      <ref url="http://secunia.com/advisories/23884" source="SECUNIA">23884</ref>
      <ref url="http://lists.debian.org/debian-security-announce/debian-security-announce-2007/msg00011.html" source="DEBIAN">DSA-1256</ref>
    </refs>
    <vuln_soft>
      <prod vendor="the_gimp_team" name="gimp_toolkit">
        <vers num="2.4.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0011" published="2007-11-05" name="CVE-2007-0011" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The web portal interface in Citrix Access Gateway (aka Citrix Advanced Access Control) before Advanced Edition 4.5 HF1 places a session ID in the URL, which allows context-dependent attackers to hijack sessions by reading "residual information", including the a referer log, browser history, or browser cache.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/24975" source="BID" patch="1">24975</ref>
      <ref url="http://secunia.com/advisories/26143" source="SECUNIA" patch="1" adv="1">26143</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/35510" source="XF">citrix-access-unspeci-information-disclosure(35510)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2583" source="VUPEN">ADV-2007-2583</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/482626/100/100/threaded" source="BUGTRAQ">20071022 Corsaire Security Advisory - Citrix Access Gateway session ID disclosure issue</ref>
      <ref url="http://support.citrix.com/article/CTX113814" source="CONFIRM">http://support.citrix.com/article/CTX113814</ref>
      <ref url="http://support.citrix.com/article/CTX112803" source="CONFIRM">http://support.citrix.com/article/CTX112803</ref>
      <ref url="http://securitytracker.com/id?1018435" source="SECTRACK">1018435</ref>
      <ref url="http://osvdb.org/45288" source="OSVDB">45288</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citrix" name="access_gateway">
        <vers num="4.0"/>
        <vers num="4.2"/>
        <vers num="4.5" edition=""/>
        <vers num="4.5" edition=":standard"/>
        <vers num="4.5" edition=":advanced"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0012" published="2008-01-09" name="CVE-2007-0012" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Sun JRE 5.0 before update 14 allows remote attackers to cause a denial of service (Internet Explorer crash) via an object tag with an encoded applet and an undefined name attribute, which triggers a NULL pointer dereference in jpiexp32.dll when the applet is decoded and passed to the JVM.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39549" source="XF">sun-java-jpiexp32-dos(39549)</ref>
      <ref url="http://www.securityfocus.com/bid/27185" source="BID">27185</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485942/100/0/threaded" source="BUGTRAQ">20080108 Corsaire Security Advisory: Sun J2RE DoS issue</ref>
      <ref url="http://securityreason.com/securityalert/3527" source="SREASON">3527</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jre">
        <vers prev="1" num="1.5.0" edition="update10"/>
        <vers prev="1" num="1.5.0" edition="update11"/>
        <vers prev="1" num="1.5.0" edition="update12"/>
        <vers prev="1" num="1.5.0" edition="update13"/>
        <vers prev="1" num="1.5.0" edition="update7"/>
        <vers prev="1" num="1.5.0" edition="update8"/>
        <vers prev="1" num="1.5.0" edition="update9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0014" reject="1" published="2007-01-16" name="CVE-2007-0014" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">ChainKey Java Code Protection allows attackers to decompile Java class files via a Java class loader with a modified defineClass method that saves the bytecode to a file before it is passed to the JVM.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456734/100/0/threaded" source="BUGTRAQ">20070112 Re: Corsaire Security Advisory: ChainKey Java Code Protection Bypass issue</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456712/100/0/threaded" source="BUGTRAQ" adv="1">20070112 Corsaire Security Advisory: ChainKey Java Code Protection Bypass issue</ref>
      <ref url="http://osvdb.org/33473" source="OSVDB">33473</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="chainkey_java_code_protection">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0015" published="2007-01-01" name="CVE-2007-0015" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/442497" source="CERT-VN" patch="1">VU#442497</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-005A.html" source="CERT">TA07-005A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31203" source="XF" patch="1">quicktime-rtsp-url-bo(31203)</ref>
      <ref url="http://secunia.com/advisories/23540" source="SECUNIA" patch="1" adv="1">23540</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0001" source="VUPEN">ADV-2007-0001</ref>
      <ref url="http://www.securityfocus.com/bid/21829" source="BID">21829</ref>
      <ref url="http://securitytracker.com/id?1017461" source="SECTRACK">1017461</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-01-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-01-01-2007.html</ref>
      <ref url="http://landonf.bikemonkey.org/code/macosx/MOAB_Day_1.20070102060815.15950.zadder.local.html" source="MISC">http://landonf.bikemonkey.org/code/macosx/MOAB_Day_1.20070102060815.15950.zadder.local.html</ref>
      <ref url="http://www.osvdb.org/31023" source="OSVDB">31023</ref>
      <ref url="http://secunia.com/blog/7/" source="MISC">http://secunia.com/blog/7/</ref>
      <ref url="http://milw0rm.com/exploits/3064" source="MILW0RM">3064</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Jan/msg00000.html" source="APPLE">APPLE-SA-2007-01-23</ref>
      <ref url="http://isc.sans.org/diary.html?storyid=2094" source="MISC">http://isc.sans.org/diary.html?storyid=2094</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=304989" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=304989</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0016" published="2007-01-02" name="CVE-2007-0016" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in MoviePlay 4.76 allows remote attackers to execute arbitrary code via a long filename in a LST file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21840" source="BID">21840</ref>
      <ref url="http://www.milw0rm.com/exploits/4051" source="MILW0RM">4051</ref>
      <ref url="http://secunia.com/advisories/22959" source="SECUNIA" adv="1">22959</ref>
      <ref url="http://osvdb.org/32547" source="OSVDB">32547</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netfarer" name="movieplay">
        <vers num="4.76"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0017" published="2007-01-02" name="CVE-2007-0017" modified="2012-01-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in (1) the cdio_log_handler function in modules/access/cdda/access.c in the CDDA (libcdda_plugin) plugin, and the (2) cdio_log_handler and (3) vcd_log_handler functions in modules/access/vcdx/access.c in the VCDX (libvcdx_plugin) plugin, in VideoLAN VLC 0.7.0 through 0.8.6 allow user-assisted remote attackers to execute arbitrary code via format string specifiers in an invalid URI, as demonstrated by a udp://-- URI in an M3U file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.videolan.org/patches/vlc-0.8.6-MOAB-02-01-2007.patch" source="CONFIRM" patch="1">http://www.videolan.org/patches/vlc-0.8.6-MOAB-02-01-2007.patch</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31226" source="XF">vlcmediaplayer-udp-format-string(31226)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0026" source="VUPEN" adv="1">ADV-2007-0026</ref>
      <ref url="http://www.videolan.org/sa0701.html" source="CONFIRM" adv="1">http://www.videolan.org/sa0701.html</ref>
      <ref url="http://www.via.ecp.fr/via/ml/vlc-devel/2007-01/msg00005.html" source="MLIST">[vlc-devel] 20070102 Security hole in VLC media player for Mac...</ref>
      <ref url="http://www.securityfocus.com/bid/21852" source="BID">21852</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_13_xine.html" source="SUSE">SUSE-SA:2007:013</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1252" source="DEBIAN">DSA-1252</ref>
      <ref url="http://trac.videolan.org/vlc/changeset/18481" source="CONFIRM">http://trac.videolan.org/vlc/changeset/18481</ref>
      <ref url="http://securitytracker.com/id?1017464" source="SECTRACK">1017464</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200701-24.xml" source="GENTOO">GLSA-200701-24</ref>
      <ref url="http://secunia.com/advisories/23971" source="SECUNIA" adv="1">23971</ref>
      <ref url="http://secunia.com/advisories/23910" source="SECUNIA" adv="1">23910</ref>
      <ref url="http://secunia.com/advisories/23829" source="SECUNIA" adv="1">23829</ref>
      <ref url="http://secunia.com/advisories/23592" source="SECUNIA" adv="1">23592</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-02-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-02-01-2007.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14313" source="OVAL">oval:org.mitre.oval:def:14313</ref>
      <ref url="http://osvdb.org/31163" source="OSVDB">31163</ref>
      <ref url="http://landonf.bikemonkey.org/code/macosx/MOAB_Day_2.20070103045559.6753.timor.html" source="MISC">http://landonf.bikemonkey.org/code/macosx/MOAB_Day_2.20070103045559.6753.timor.html</ref>
      <ref url="http://applefun.blogspot.com/2007/01/moab-02-01-2007-vlc-media-player-udp.html" source="MISC">http://applefun.blogspot.com/2007/01/moab-02-01-2007-vlc-media-player-udp.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="videolan" name="vlc_media_player">
        <vers num="0.7.0"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.8.0"/>
        <vers num="0.8.1"/>
        <vers num="0.8.2"/>
        <vers num="0.8.4"/>
        <vers num="0.8.4a"/>
        <vers num="0.8.5"/>
        <vers num="0.8.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0018" published="2007-01-24" name="CVE-2007-0018" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and NCTDialogicVoice; (2) Magic Audio Recorder, Music Editor, and Audio Converter; (3) Aurora Media Workshop; DB Audio Mixer And Editor; (4) J. Hepple Products including Fx Audio Editor and others; (5) EXPStudio Audio Editor; (6) iMesh; (7) Quikscribe; (8) RMBSoft AudioConvert and SoundEdit Pro 2.1; (9) CDBurnerXP; (10) Code-it Software Wave MP3 Editor and aBasic Editor; (11) Movavi VideoMessage, DVD to iPod, and others; (12) SoftDiv Software Dexster, iVideoMAX, and others; (13) Sienzo Digital Music Mentor (DMM); (14) MP3 Normalizer; (15) Roemer Software FREE and Easy Hi-Q Recorder, and Easy Hi-Q Converter; (16) Audio Edit Magic; (17) Joshua Video and Audio Converter; (18) Virtual CD; (19) Cheetah CD and DVD Burner; (20) Mystik Media AudioEdit Deluxe, Blaze Media, and others; (21) Power Audio Editor; (22) DanDans Digital Media Full Audio Converter, Music Editing Master, and others; (23) Xrlly Software Text to Speech Makerand Arial Sound Recorder / Audio Converter; (24) Absolute Sound Recorder, Video to Audio Converter, and MP3 Splitter; (25) Easy Ringtone Maker; (26) RecordNRip; (27) McFunSoft iPod Audio Studio, Audio Recorder for Free, and others; (28) MP3 WAV Converter; (29) BearShare 6.0.2.26789; and (30) Oracle Siebel SimBuilder and CRM 7.x.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1" bound="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/292713" source="CERT-VN">VU#292713</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0310" source="VUPEN">ADV-2007-0310</ref>
      <ref url="http://secunia.com/secunia_research/2007-9/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-9/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-8/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-8/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-7/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-7/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-6/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-6/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-5/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-5/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-4/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-4/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-34/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-34/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-33/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-33/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-32/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-32/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-31/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-31/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-30/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-30/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-3/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-3/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-29/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-29/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-28/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-28/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-27/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-27/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-26/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-26/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-25/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-25/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-24/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-24/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-23/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-23/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-22/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-22/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-21/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-21/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-20/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-20/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-2/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-2/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-19/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-19/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-18/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-18/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-17/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-17/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-16/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-16/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-15/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-15/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-14/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-14/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-13/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-13/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-12/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-12/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-11/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-11/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-10/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-10/advisory/</ref>
      <ref url="http://secunia.com/blog/6/" source="MISC" adv="1">http://secunia.com/blog/6/</ref>
      <ref url="http://secunia.com/advisories/30459" source="SECUNIA">30459</ref>
      <ref url="http://secunia.com/advisories/30450" source="SECUNIA">30450</ref>
      <ref url="http://secunia.com/advisories/30447" source="SECUNIA">30447</ref>
      <ref url="http://secunia.com/advisories/30446" source="SECUNIA">30446</ref>
      <ref url="http://secunia.com/advisories/30439" source="SECUNIA">30439</ref>
      <ref url="http://secunia.com/advisories/30424" source="SECUNIA">30424</ref>
      <ref url="http://secunia.com/advisories/30406" source="SECUNIA">30406</ref>
      <ref url="http://secunia.com/advisories/23568" source="SECUNIA" adv="1">23568</ref>
      <ref url="http://secunia.com/advisories/23557" source="SECUNIA" adv="1">23557</ref>
      <ref url="http://secunia.com/advisories/23553" source="SECUNIA" adv="1">23553</ref>
      <ref url="http://secunia.com/advisories/23552" source="SECUNIA" adv="1">23552</ref>
      <ref url="http://secunia.com/advisories/23551" source="SECUNIA" adv="1">23551</ref>
      <ref url="http://secunia.com/advisories/23543" source="SECUNIA" adv="1">23543</ref>
      <ref url="http://secunia.com/advisories/23534" source="SECUNIA" adv="1">23534</ref>
      <ref url="http://secunia.com/advisories/23532" source="SECUNIA" adv="1">23532</ref>
      <ref url="http://secunia.com/advisories/23530" source="SECUNIA" adv="1">23530</ref>
      <ref url="http://secunia.com/advisories/23516" source="SECUNIA" adv="1">23516</ref>
      <ref url="http://secunia.com/advisories/23511" source="SECUNIA" adv="1">23511</ref>
      <ref url="http://secunia.com/advisories/23495" source="SECUNIA" adv="1">23495</ref>
      <ref url="http://secunia.com/advisories/23493" source="SECUNIA" adv="1">23493</ref>
      <ref url="http://secunia.com/advisories/23485" source="SECUNIA" adv="1">23485</ref>
      <ref url="http://secunia.com/advisories/23475" source="SECUNIA" adv="1">23475</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31707" source="XF">nctaudiofile2-multiple-bo(31707)</ref>
      <ref url="http://www.securityfocus.com/bid/23892" source="BID">23892</ref>
      <ref url="http://www.securityfocus.com/bid/22196" source="BID">22196</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457965/100/200/threaded" source="BUGTRAQ">20070124 Re: Secunia Research: NCTsoft Products NCTAudioFile2 ActiveXControl Buffer Overflow</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457940/100/200/threaded" source="BUGTRAQ">20070124 Secunia Research: Sienzo Digital Music Mentor NCTAudioFile2ActiveX Control Buffer Overflow</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457936/100/200/threaded" source="BUGTRAQ">20070124 Secunia Research: NCTsoft Products NCTAudioFile2 ActiveX ControlBuffer Overflow</ref>
      <ref url="http://secunia.com/secunia_research/2007-50/advisory/" source="MISC">http://secunia.com/secunia_research/2007-50/advisory/</ref>
      <ref url="http://secunia.com/advisories/28407" source="SECUNIA">28407</ref>
      <ref url="http://secunia.com/advisories/26101" source="SECUNIA">26101</ref>
      <ref url="http://secunia.com/advisories/26100" source="SECUNIA">26100</ref>
      <ref url="http://secunia.com/advisories/26046" source="SECUNIA">26046</ref>
      <ref url="http://secunia.com/advisories/25993" source="SECUNIA">25993</ref>
      <ref url="http://secunia.com/advisories/23795" source="SECUNIA">23795</ref>
      <ref url="http://secunia.com/advisories/23753" source="SECUNIA">23753</ref>
      <ref url="http://secunia.com/advisories/23745" source="SECUNIA">23745</ref>
      <ref url="http://secunia.com/advisories/23565" source="SECUNIA">23565</ref>
      <ref url="http://secunia.com/advisories/23562" source="SECUNIA">23562</ref>
      <ref url="http://secunia.com/advisories/23561" source="SECUNIA">23561</ref>
      <ref url="http://secunia.com/advisories/23560" source="SECUNIA">23560</ref>
      <ref url="http://secunia.com/advisories/23558" source="SECUNIA">23558</ref>
      <ref url="http://secunia.com/advisories/23554" source="SECUNIA">23554</ref>
      <ref url="http://secunia.com/advisories/23550" source="SECUNIA">23550</ref>
      <ref url="http://secunia.com/advisories/23548" source="SECUNIA">23548</ref>
      <ref url="http://secunia.com/advisories/23546" source="SECUNIA">23546</ref>
      <ref url="http://secunia.com/advisories/23544" source="SECUNIA">23544</ref>
      <ref url="http://secunia.com/advisories/23542" source="SECUNIA">23542</ref>
      <ref url="http://secunia.com/advisories/23541" source="SECUNIA">23541</ref>
      <ref url="http://secunia.com/advisories/23536" source="SECUNIA">23536</ref>
      <ref url="http://secunia.com/advisories/23535" source="SECUNIA">23535</ref>
      <ref url="http://secunia.com/advisories/22922" source="SECUNIA">22922</ref>
    </refs>
    <vuln_soft>
      <prod vendor="altdo" name="convert_mp3_master">
        <vers num="1.1"/>
      </prod>
      <prod vendor="altdo" name="mp3_record_and_edit_audio_master">
        <vers num="1.2"/>
      </prod>
      <prod vendor="americanshareware" name="mp3_wav_converter">
        <vers num="3.1.8"/>
      </prod>
      <prod vendor="audio_edit_magic" name="audio_edit_magic">
        <vers num="9.2.3_389"/>
      </prod>
      <prod vendor="bearshare" name="bearshare">
        <vers num="6.0.2.26789"/>
      </prod>
      <prod vendor="cdburnerxp" name="cdburnerxp_pro">
        <vers num="3.0.116"/>
      </prod>
      <prod vendor="cheetahburner" name="cheetah_cd_burner">
        <vers num="3.56"/>
      </prod>
      <prod vendor="cheetahburner" name="cheetah_dvd_burner">
        <vers num="1.79"/>
      </prod>
      <prod vendor="code-it_softare" name="abasic_editor">
        <vers num="10.1"/>
      </prod>
      <prod vendor="code-it_softare" name="wave_mp3_editor">
        <vers num="10.1"/>
      </prod>
      <prod vendor="dandans_digital_media_products" name="easy_audio_editor">
        <vers num="7.4"/>
      </prod>
      <prod vendor="dandans_digital_media_products" name="full_audio_converter">
        <vers num="4.2"/>
      </prod>
      <prod vendor="dandans_digital_media_products" name="music_editing_master">
        <vers num="5.2"/>
      </prod>
      <prod vendor="dandans_digital_media_products" name="visual_video_converter">
        <vers num="4.4"/>
      </prod>
      <prod vendor="digital_borneo" name="audio_mixer_and_editor">
        <vers num="1.1.0"/>
      </prod>
      <prod vendor="easy_ringtone_maker" name="easy_ringtone_maker">
        <vers num="2.0.5"/>
      </prod>
      <prod vendor="expstudio" name="audio_editor">
        <vers num="4.0.2"/>
      </prod>
      <prod vendor="iaudiosoft.com" name="absolute_mp3_splitter">
        <vers num="2.5.4"/>
      </prod>
      <prod vendor="iaudiosoft.com" name="absolute_sound_recorder">
        <vers num="3.4.5"/>
      </prod>
      <prod vendor="iaudiosoft.com" name="absolute_video_to_audio_converter">
        <vers num="2.7.9"/>
      </prod>
      <prod vendor="imesh.com" name="imesh">
        <vers num="7.0.2.26789"/>
      </prod>
      <prod vendor="j_hepple_products" name="fx_audio_concat">
        <vers num="1.2.0_beta"/>
      </prod>
      <prod vendor="j_hepple_products" name="fx_audio_editor">
        <vers num="4.7.11"/>
      </prod>
      <prod vendor="j_hepple_products" name="fx_audio_tools">
        <vers num="7.3.4"/>
      </prod>
      <prod vendor="j_hepple_products" name="fx_magic_music">
        <vers num="5.7.7"/>
      </prod>
      <prod vendor="j_hepple_products" name="fx_movie_joiner">
        <vers num="6.2.8"/>
      </prod>
      <prod vendor="j_hepple_products" name="fx_movie_joiner_and_splitter">
        <vers num="6.2.8"/>
      </prod>
      <prod vendor="j_hepple_products" name="fx_movie_splitter">
        <vers num="6.4.7"/>
      </prod>
      <prod vendor="j_hepple_products" name="fx_new_sound">
        <vers num="5.1.1"/>
      </prod>
      <prod vendor="j_hepple_products" name="fx_video_converter">
        <vers num="7.51.21"/>
      </prod>
      <prod vendor="joshua_mediasoft" name="audio_convertor_plus">
        <vers num="2.2"/>
      </prod>
      <prod vendor="joshua_mediasoft" name="video_converter_plus">
        <vers num="3.01"/>
      </prod>
      <prod vendor="magicvideosoftare" name="magic_audio_converter">
        <vers num="8.2.6_build_719"/>
      </prod>
      <prod vendor="magicvideosoftare" name="magic_audio_recorder">
        <vers num="5.3.7"/>
      </prod>
      <prod vendor="magicvideosoftare" name="magic_music_editor">
        <vers num="5.2.2"/>
      </prod>
      <prod vendor="mcfunsoft" name="audio_editor">
        <vers num="6.3.3_build_489"/>
      </prod>
      <prod vendor="mcfunsoft" name="audio_recorder_for_free">
        <vers num="6.1"/>
      </prod>
      <prod vendor="mcfunsoft" name="audio_studio">
        <vers num="6.6.3_build_479"/>
      </prod>
      <prod vendor="mcfunsoft" name="ipod_audio_studio">
        <vers num="6.2.4"/>
      </prod>
      <prod vendor="mcfunsoft" name="ipod_music_converter">
        <vers num="5.1"/>
      </prod>
      <prod vendor="mcfunsoft" name="recording_to_ipod_solution">
        <vers num="5.1"/>
      </prod>
      <prod vendor="mediatox" name="aurora_media_workshop">
        <vers num="3.3.25"/>
      </prod>
      <prod vendor="movavi" name="chiliburner">
        <vers num="2.3"/>
      </prod>
      <prod vendor="movavi" name="convertmovie">
        <vers num="4.4"/>
      </prod>
      <prod vendor="movavi" name="dvd_to_ipod">
        <vers num="1.0"/>
      </prod>
      <prod vendor="movavi" name="splitmovie">
        <vers num="1.4"/>
      </prod>
      <prod vendor="movavi" name="suite">
        <vers num="3.5"/>
      </prod>
      <prod vendor="movavi" name="videomessage">
        <vers num="1.0"/>
      </prod>
      <prod vendor="mp3-soft" name="mp3_normalizer">
        <vers num="1.03"/>
      </prod>
      <prod vendor="mystik_media_products" name="audioedit_deluxe">
        <vers num="4.10"/>
      </prod>
      <prod vendor="mystik_media_products" name="blaze_media_pro">
        <vers num="7.0"/>
      </prod>
      <prod vendor="mystik_media_products" name="blaze_mediaconvert">
        <vers num="3.4"/>
      </prod>
      <prod vendor="mystik_media_products" name="contextconvert_pro">
        <vers num="3.1"/>
      </prod>
      <prod vendor="nctsoft_products" name="nctaudioeditor">
        <vers num="2.7.1"/>
      </prod>
      <prod vendor="nctsoft_products" name="nctaudiofile2">
        <vers num=""/>
      </prod>
      <prod vendor="nctsoft_products" name="nctaudiostudio">
        <vers num="2.7.1"/>
      </prod>
      <prod vendor="nctsoft_products" name="nctdialogicvoice">
        <vers num="2.7.1"/>
      </prod>
      <prod vendor="nextlevel_systems" name="audio_editor_gold">
        <vers num="9.2.5_build_424"/>
      </prod>
      <prod vendor="nextlevel_systems" name="audio_studio_gold">
        <vers num="7.0.1.1_build_500"/>
      </prod>
      <prod vendor="quikscribe" name="quikscribe_player">
        <vers num="5.022.05"/>
      </prod>
      <prod vendor="quikscribe" name="quikscribe_recorder">
        <vers num="5.021.29"/>
      </prod>
      <prod vendor="recordnrip" name="recordnrip">
        <vers num="1.0"/>
      </prod>
      <prod vendor="rmbsoft" name="audioconvert">
        <vers num="3.1.0.125"/>
      </prod>
      <prod vendor="rmbsoft" name="soundedit_pro">
        <vers num="2.1"/>
      </prod>
      <prod vendor="roemer_software" name="easy_hi-q_converter">
        <vers num="1.7"/>
      </prod>
      <prod vendor="roemer_software" name="easy_hi-q_recorder">
        <vers num="2.0"/>
      </prod>
      <prod vendor="roemer_software" name="free_hi-q_recorder">
        <vers num="1.9"/>
      </prod>
      <prod vendor="sienzo" name="digital_music_mentor">
        <vers num="2.6.0.3"/>
      </prod>
      <prod vendor="smart_media_systems" name="power_audio_editor">
        <vers num="11.0.1"/>
      </prod>
      <prod vendor="softdiv_softare" name="dexster">
        <vers num="3.0"/>
      </prod>
      <prod vendor="softdiv_softare" name="ivideomax">
        <vers num="3.9"/>
      </prod>
      <prod vendor="softdiv_softare" name="mp3_to_wav_converter">
        <vers num="3.0"/>
      </prod>
      <prod vendor="softdiv_softare" name="snosh">
        <vers num="1.4"/>
      </prod>
      <prod vendor="softdiv_softare" name="videozilla">
        <vers num="2.5"/>
      </prod>
      <prod vendor="virtual_cd" name="virtual_cd">
        <vers num="6.0.0.7"/>
        <vers num="7.1.0.2"/>
        <vers num="8.0.0.6"/>
      </prod>
      <prod vendor="virtual_cd" name="virtual_cd_file_server">
        <vers num="7.1.0.3"/>
      </prod>
      <prod vendor="xrlly_software" name="arial_audio_converter">
        <vers num="2.3.40"/>
      </prod>
      <prod vendor="xrlly_software" name="arial_sound_recorder">
        <vers num="1.4.3"/>
      </prod>
      <prod vendor="xrlly_software" name="text_to_speech_maker">
        <vers num="1.3.8"/>
      </prod>
      <prod vendor="xwaver.com" name="magic_audio_editor_pro">
        <vers num="10.3.1_build_476"/>
      </prod>
      <prod vendor="xwaver.com" name="magic_music_studio_pro">
        <vers num="7.0.2.1_build_500"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0019" published="2007-01-19" name="CVE-2007-0019" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in rumpusd in Rumpus 5.1 and earlier (1) allow remote authenticated users to execute arbitrary code via a long LIST command and other unspecified requests to the FTP service, and (2) allow remote attackers to execute arbitrary code via unspecified requests to the HTTP service.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31594" source="XF">rumpus-ftp-http-bo(31594)</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-18-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-18-01-2007.html</ref>
      <ref url="http://osvdb.org/32692" source="OSVDB">32692</ref>
      <ref url="http://osvdb.org/32689" source="OSVDB">32689</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31594" source="XF">rumpus-ftp-service-bo(31594)</ref>
      <ref url="http://secunia.com/advisories/23842" source="SECUNIA">23842</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxum_development_corporation" name="rumpus_ftp_server">
        <vers prev="1" num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0020" published="2007-01-23" name="CVE-2007-0020" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the SFTP protocol handler for Panic Transmit (Transmit.app) up to 3.5.5 allows remote attackers to execute arbitrary code via a long ftps:// URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0273" source="VUPEN">ADV-2007-0273</ref>
      <ref url="http://www.securityfocus.com/bid/22145" source="BID">22145</ref>
      <ref url="http://secunia.com/advisories/23861" source="SECUNIA" adv="1">23861</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-19-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-19-01-2007.html</ref>
      <ref url="http://osvdb.org/32694" source="OSVDB">32694</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31673" source="XF">transmit-url-handler-bo(31673)</ref>
      <ref url="http://milw0rm.com/exploits/3160" source="MILW0RM">3160</ref>
    </refs>
    <vuln_soft>
      <prod vendor="panic_transmit" name="panic_transmit">
        <vers prev="1" num="3.5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0021" published="2007-01-22" name="CVE-2007-0021" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in Apple iChat 3.1.6 allows remote attackers to cause a denial of service (null pointer dereference and application crash) and possibly execute arbitrary code via format string specifiers in an aim:// URI.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-047A.html" source="CERT">TA07-047A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/794752" source="CERT-VN">VU#794752</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0274" source="VUPEN">ADV-2007-0274</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-20-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-20-01-2007.html</ref>
      <ref url="http://osvdb.org/32715" source="OSVDB">32715</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31679" source="XF">ichat-aim-format-string(31679)</ref>
      <ref url="http://www.securitytracker.com/id?1017661" source="SECTRACK">1017661</ref>
      <ref url="http://www.securityfocus.com/bid/22146" source="BID">22146</ref>
      <ref url="http://secunia.com/advisories/24198" source="SECUNIA">24198</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html" source="APPLE">APPLE-SA-2007-02-15</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305102" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305102</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="ichat">
        <vers num="3.1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0022" published="2007-01-22" name="CVE-2007-0022" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in writeconfig in Apple Mac OS X 10.4.8 allows local users to gain privileges via a modified PATH that points to a malicious launchctl program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" source="CERT">TA07-109A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31677" source="XF">macos-writeconfig-privilege-escalation(31677)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1470" source="VUPEN">ADV-2007-1470</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0074" source="VUPEN">ADV-2007-0074</ref>
      <ref url="http://www.securitytracker.com/id?1017941" source="SECTRACK">1017941</ref>
      <ref url="http://www.securityfocus.com/bid/22148" source="BID">22148</ref>
      <ref url="http://www.osvdb.org/31605" source="OSVDB">31605</ref>
      <ref url="http://secunia.com/advisories/24966" source="SECUNIA">24966</ref>
      <ref url="http://secunia.com/advisories/23793" source="SECUNIA">23793</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-21-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-21-01-2007.html</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" source="APPLE">APPLE-SA-2007-04-19</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305391" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305391</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0023" published="2007-01-23" name="CVE-2007-0023" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">The CFUserNotificationSendRequest function in UserNotificationCenter.app in Apple Mac OS X 10.4.8, when used in combination with diskutil, allows local users to gain privileges via a malicious InputManager in Library/InputManagers in a user's home directory, which is executed when Cocoa applications attempt to notify the user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-047A.html" source="CERT">TA07-047A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/315856" source="CERT-VN">VU#315856</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0074" source="VUPEN">ADV-2007-0074</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-22-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-22-01-2007.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31676" source="XF">macos-inputmanager-privilege-escalation(31676)</ref>
      <ref url="http://www.securityfocus.com/bid/22188" source="BID">22188</ref>
      <ref url="http://www.osvdb.org/32695" source="OSVDB">32695</ref>
      <ref url="http://securitytracker.com/id?1017542" source="SECTRACK">1017542</ref>
      <ref url="http://secunia.com/advisories/24198" source="SECUNIA">24198</ref>
      <ref url="http://secunia.com/advisories/23846" source="SECUNIA">23846</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html" source="APPLE">APPLE-SA-2007-02-15</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305102" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305102</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0024" published="2007-01-09" name="CVE-2007-0024" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in the Vector Markup Language (VML) implementation (vgx.dll) in Microsoft Internet Explorer 5.01, 6, and 7 on Windows 2000 SP4, XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted web page that contains unspecified integer properties that cause insufficient memory allocation and trigger a buffer overflow, aka the "VML Buffer Overrun Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/122084" source="CERT-VN" patch="1">VU#122084</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" source="CERT">TA07-009A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31287" source="XF" patch="1">ie-vml-record-bo(31287)</ref>
      <ref url="http://www.securityfocus.com/bid/21930" source="BID" patch="1">21930</ref>
      <ref url="http://www.osvdb.org/31250" source="OSVDB" patch="1">31250</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-004.mspx" source="MS" patch="1">MS07-004</ref>
      <ref url="http://support.microsoft.com/?kbid=929969" source="MSKB" patch="1">929969</ref>
      <ref url="http://securitytracker.com/id?1017489" source="SECTRACK" patch="1">1017489</ref>
      <ref url="http://secunia.com/advisories/23677" source="SECUNIA" patch="1" adv="1">23677</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=462" source="IDEFENSE" patch="1" adv="1">20070109 Microsoft Windows VML Element Integer Overflow Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0129" source="VUPEN">ADV-2007-0129</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0105" source="VUPEN">ADV-2007-0105</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">SSRT071296</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">SSRT071296</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457164/100/0/threaded" source="BUGTRAQ">20070117 Re: MS07-004 VML Integer Overflow Exploit</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457053/100/0/threaded" source="BUGTRAQ">20070116 MS07-004 VML Integer Overflow Exploit</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-009.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-009.htm</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1058" source="OVAL" sig="1">oval:org.mitre.oval:def:1058</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp4"/>
        <vers num="6.0" edition="sp1"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0025" published="2007-02-13" name="CVE-2007-0025" modified="2011-06-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The MFC component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 and Visual Studio .NET 2000, 2002 SP1, 2003, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption. NOTE: this might be due to a stack-based buffer overflow in the AfxOleSetEditMenu function in MFC42u.dll.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" source="CERT">TA07-044A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/932041" source="CERT-VN">VU#932041</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-012.mspx" source="MS" patch="1">MS07-012</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0581" source="VUPEN" adv="1">ADV-2007-0581</ref>
      <ref url="http://www.securitytracker.com/id?1017638" source="SECTRACK">1017638</ref>
      <ref url="http://www.securityfocus.com/bid/22476" source="BID">22476</ref>
      <ref url="http://www.osvdb.org/31887" source="OSVDB">31887</ref>
      <ref url="http://secunia.com/advisories/24150" source="SECUNIA" adv="1">24150</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:157" source="OVAL" sig="1" adv="1">oval:org.mitre.oval:def:157</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visual_studio_.net">
        <vers num="2000" edition="sp1"/>
        <vers num="2003" edition="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="2000" edition="sp4"/>
        <vers num="2003" edition="sp2"/>
        <vers num="xp_sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0026" published="2007-02-13" name="CVE-2007-0026" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">The OLE Dialog component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" source="CERT">TA07-044A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/497756" source="CERT-VN">VU#497756</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-011.mspx" source="MS" patch="1">MS07-011</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0580" source="VUPEN">ADV-2007-0580</ref>
      <ref url="http://www.securitytracker.com/id?1017637" source="SECTRACK">1017637</ref>
      <ref url="http://www.securityfocus.com/bid/22483" source="BID">22483</ref>
      <ref url="http://www.osvdb.org/31885" source="OSVDB">31885</ref>
      <ref url="http://secunia.com/advisories/24147" source="SECUNIA">24147</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:540" source="OVAL" sig="1">oval:org.mitre.oval:def:540</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="sp1"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:tablet_pc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0027" published="2007-01-09" name="CVE-2007-0027" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via malformed IMDATA records that trigger memory corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" source="CERT">TA07-009A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/749964" source="CERT-VN">VU#749964</ref>
      <ref url="http://www.securityfocus.com/bid/21856" source="BID" patch="1">21856</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-002.mspx" source="MS" patch="1" adv="1">MS07-002</ref>
      <ref url="http://securitytracker.com/id?1017487" source="SECTRACK" patch="1">1017487</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0103" source="VUPEN">ADV-2007-0103</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">HPSBST02184</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">HPSBST02184</ref>
      <ref url="http://www.osvdb.org/31255" source="OSVDB">31255</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:119" source="OVAL" sig="1">oval:org.mitre.oval:def:119</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000"/>
        <vers num="2002"/>
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp2"/>
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
        <vers num="v.x" edition=""/>
        <vers num="v.x" edition=":mac"/>
        <vers num="xp" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2004"/>
        <vers num="2005"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0028" published="2007-01-09" name="CVE-2007-0028" modified="2011-10-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not properly handle certain opcodes, which allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file, which results in an "Improper Memory Access Vulnerability."  NOTE: an early disclosure of this issue used CVE-2006-3432, but only CVE-2007-0028 should be used.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/493185" source="CERT-VN" patch="1">VU#493185</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" source="CERT">TA07-009A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-002.mspx" source="MS" patch="1" adv="1">MS07-002</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0103" source="VUPEN" adv="1">ADV-2007-0103</ref>
      <ref url="http://www.securityfocus.com/bid/21952" source="BID">21952</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">HPSBST02184</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">SSRT071296</ref>
      <ref url="http://www.osvdb.org/31249" source="OSVDB">31249</ref>
      <ref url="http://www.fortinet.com/FortiGuardCenter/advisory/FGA-2007-01.html" source="MISC">http://www.fortinet.com/FortiGuardCenter/advisory/FGA-2007-01.html</ref>
      <ref url="http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-30.html" source="MISC">http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-30.html</ref>
      <ref url="http://securitytracker.com/id?1017485" source="SECTRACK">1017485</ref>
      <ref url="http://secunia.com/advisories/23676" source="SECUNIA" adv="1">23676</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:768" source="OVAL" sig="1">oval:org.mitre.oval:def:768</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000"/>
        <vers num="2002"/>
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp2"/>
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
        <vers num="v.x" edition=""/>
        <vers num="v.x" edition=":mac"/>
        <vers num="xp" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2004"/>
        <vers num="2005"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0029" published="2007-01-09" name="CVE-2007-0029" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a malformed string, aka "Excel Malformed String Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" source="CERT">TA07-009A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-002.mspx" source="MS" patch="1" adv="1">MS07-002</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0103" source="VUPEN">ADV-2007-0103</ref>
      <ref url="http://www.securityfocus.com/bid/21877" source="BID">21877</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">HPSBST02184</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">HPSBST02184</ref>
      <ref url="http://www.osvdb.org/31256" source="OSVDB">31256</ref>
      <ref url="http://securitytracker.com/id?1017487" source="SECTRACK">1017487</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1102" source="OVAL" sig="1">oval:org.mitre.oval:def:1102</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000"/>
        <vers num="2002"/>
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp2"/>
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
        <vers num="v.x" edition=""/>
        <vers num="v.x" edition=":mac"/>
        <vers num="xp" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2004"/>
        <vers num="2005"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0030" published="2007-01-09" name="CVE-2007-0030" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via an Excel file with an out-of-range Column field in certain BIFF8 record types, which references arbitrary memory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" source="CERT">TA07-009A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/302836" source="CERT-VN">VU#302836</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-002.mspx" source="MS" patch="1" adv="1">MS07-002</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=460" source="IDEFENSE" patch="1" adv="1">20070109 Microsoft Excel Invalid Column Heap Corruption Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0103" source="VUPEN">ADV-2007-0103</ref>
      <ref url="http://www.securityfocus.com/bid/21925" source="BID">21925</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">HPSBST02184</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">HPSBST02184</ref>
      <ref url="http://www.osvdb.org/31257" source="OSVDB">31257</ref>
      <ref url="http://securitytracker.com/id?1017487" source="SECTRACK">1017487</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:323" source="OVAL" sig="1">oval:org.mitre.oval:def:323</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000"/>
        <vers num="2002"/>
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp2"/>
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
        <vers num="v.x" edition=""/>
        <vers num="v.x" edition=":mac"/>
        <vers num="xp" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2004"/>
        <vers num="2005"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0031" published="2007-01-09" name="CVE-2007-0031" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a BIFF8 spreadsheet with a PALETTE record that contains a large number of entries.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" source="CERT">TA07-009A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/625532" source="CERT-VN">VU#625532</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-002.mspx" source="MS" patch="1" adv="1">MS07-002</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=461" source="IDEFENSE" patch="1" adv="1">20070109 Microsoft Excel Long Palette Heap Overflow Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0103" source="VUPEN">ADV-2007-0103</ref>
      <ref url="http://www.securityfocus.com/bid/21922" source="BID">21922</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">SSRT071296</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">HPSBST02184</ref>
      <ref url="http://www.osvdb.org/31258" source="OSVDB">31258</ref>
      <ref url="http://securitytracker.com/id?1017487" source="SECTRACK">1017487</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:753" source="OVAL" sig="1">oval:org.mitre.oval:def:753</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000"/>
        <vers num="2002"/>
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp2"/>
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
        <vers num="v.x" edition=""/>
        <vers num="v.x" edition=":mac"/>
        <vers num="xp" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2004"/>
        <vers num="2005"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0033" published="2007-01-09" name="CVE-2007-0033" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Outlook 2002 and 2003 allows user-assisted remote attackers to execute arbitrary code via a malformed VEVENT record in an .iCal meeting request or ICS file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" source="CERT">TA07-009A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/476900" source="CERT-VN">VU#476900</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-003.mspx" source="MS" patch="1" adv="1">MS07-003</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0104" source="VUPEN">ADV-2007-0104</ref>
      <ref url="http://www.securityfocus.com/bid/21931" source="BID">21931</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">HPSBST02184</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">HPSBST02184</ref>
      <ref url="http://www.osvdb.org/31252" source="OSVDB">31252</ref>
      <ref url="http://securitytracker.com/id?1017488" source="SECTRACK">1017488</ref>
      <ref url="http://secunia.com/advisories/23674" source="SECUNIA">23674</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:516" source="OVAL" sig="1">oval:org.mitre.oval:def:516</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp2"/>
        <vers num="xp" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="outlook">
        <vers num="2000"/>
        <vers num="2002"/>
        <vers num="2003"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0034" published="2007-01-09" name="CVE-2007-0034" modified="2011-09-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in the Advanced Search (Finder.exe) feature of Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted Outlook Saved Searches (OSS) file that triggers memory corruption, aka "Microsoft Outlook Advanced Find Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" source="CERT">TA07-009A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/271860" source="CERT-VN">VU#271860</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-003.mspx" source="MS" patch="1" adv="1">MS07-003</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0104" source="VUPEN" adv="1">ADV-2007-0104</ref>
      <ref url="http://www.securityfocus.com/bid/21936" source="BID">21936</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">HPSBST02184</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">HPSBST02184</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456589/100/0/threaded" source="BUGTRAQ">20070111 Computer Terrorism (UK) :: Incident Response Centre - Microsoft Outlook Vulnerability</ref>
      <ref url="http://www.osvdb.org/31254" source="OSVDB">31254</ref>
      <ref url="http://www.computerterrorism.com/research/ct09-01-2007.htm" source="MISC">http://www.computerterrorism.com/research/ct09-01-2007.htm</ref>
      <ref url="http://securitytracker.com/id?1017488" source="SECTRACK">1017488</ref>
      <ref url="http://secunia.com/advisories/23674" source="SECUNIA" adv="1">23674</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:153" source="OVAL" sig="1">oval:org.mitre.oval:def:153</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp2"/>
        <vers num="xp" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="outlook">
        <vers num="2000"/>
        <vers num="2002"/>
        <vers num="2003"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0035" published="2007-05-08" name="CVE-2007-0035" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly handle data in a certain array, which allows user-assisted remote attackers to execute arbitrary code, aka the "Word Array Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" source="CERT">TA07-128A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/260777" source="CERT-VN">VU#260777</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-024.mspx" source="MS" patch="1">MS07-024</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1709" source="VUPEN" adv="1">ADV-2007-1709</ref>
      <ref url="http://www.securitytracker.com/id?1018013" source="SECTRACK">1018013</ref>
      <ref url="http://www.securityfocus.com/bid/23804" source="BID">23804</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">HPSBST02214</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://www.osvdb.org/34387" source="OSVDB">34387</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1737" source="OVAL" sig="1">oval:org.mitre.oval:def:1737</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3"/>
        <vers num="2002" edition="sp3"/>
        <vers num="2003" edition="sp2"/>
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2004"/>
        <vers num="2005"/>
        <vers num="2006"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0038" published="2007-03-30" name="CVE-2007-0038" modified="2012-11-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765; if so, then CVE-2007-0038 should be preferred.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-100A.html" source="CERT">TA07-100A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-093A.html" source="CERT">TA07-093A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-089A.html" source="CERT">TA07-089A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/191609" source="CERT-VN">VU#191609</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33301" source="XF">windows-ani-code-execution(33301)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33301" source="XF">windows-ani-code-execution(33301)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1215" source="VUPEN" adv="1">ADV-2007-1215</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466186/100/200/threaded" source="HP">SSRT071354</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466186/100/200/threaded" source="HP">SSRT071354</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464460/100/100/threaded" source="BUGTRAQ">20070402 MS announces out-of-band patch for ANI 0day</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464459/100/100/threaded" source="BUGTRAQ">20070402 More information on ZERT patch for ANI 0day</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464342/100/0/threaded" source="BUGTRAQ">20070331 RE: [Full-disclosure] 0-day ANI vulnerability in Microsoft Windows(CVE-2007-0038)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464340/100/0/threaded" source="BUGTRAQ">20070331 Re: 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464339/100/0/threaded" source="BUGTRAQ">20070330 Re: 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464269/100/0/threaded" source="BUGTRAQ">20070330 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038)</ref>
      <ref url="http://www.osvdb.org/33629" source="OSVDB">33629</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/ms07-017.mspx" source="MS">MS07-017</ref>
      <ref url="http://www.determina.com/security_center/security_advisories/securityadvisory_0day_032907.asp" source="MISC" adv="1">http://www.determina.com/security_center/security_advisories/securityadvisory_0day_032907.asp</ref>
      <ref url="http://securityreason.com/securityalert/2542" source="SREASON">2542</ref>
      <ref url="http://secunia.com/advisories/24659" source="SECUNIA" adv="1">24659</ref>
      <ref url="http://milw0rm.com/exploits/3634" source="MILW0RM">3634</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-03/0470.html" source="FULLDISC">20070330 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1854" source="OVAL" sig="1">oval:org.mitre.oval:def:1854</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="gold" edition=""/>
        <vers num="gold" edition=":itanium"/>
        <vers num="gold" edition=":x64"/>
        <vers num="sp1" edition=""/>
        <vers num="sp1" edition=":itanium"/>
        <vers num="sp2" edition=""/>
        <vers num="sp2" edition=":itanium"/>
        <vers num="sp2" edition=":x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional_x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:professional_x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0039" published="2007-05-08" name="CVE-2007-0039" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 allows remote attackers to cause a denial of service (crash) via an Internet Calendar (iCal) file containing multiple X-MICROSOFT-CDO-MODPROPS (MODPROPS) properties in which the second MODPROPS is longer than the first, which triggers a NULL pointer dereference and an unhandled exception.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" source="CERT">TA07-128A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-026.mspx" source="MS" patch="1">MS07-026</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33888" source="XF">exchange-ical-dos(33888)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1711" source="VUPEN" adv="1">ADV-2007-1711</ref>
      <ref url="http://www.securitytracker.com/id?1018015" source="SECTRACK">1018015</ref>
      <ref url="http://www.securityfocus.com/bid/23808" source="BID">23808</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">HPSBST02214</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">HPSBST02214</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468047/100/0/threaded" source="BUGTRAQ">20070508 Exchange Calendar MODPROPS Denial of Service (CVE-2007-0039)</ref>
      <ref url="http://www.osvdb.org/34390" source="OSVDB">34390</ref>
      <ref url="http://www.determina.com/security.research/vulnerabilities/exchange-ical-modprops.html" source="MISC">http://www.determina.com/security.research/vulnerabilities/exchange-ical-modprops.html</ref>
      <ref url="http://secunia.com/advisories/25183" source="SECUNIA" adv="1">25183</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-May/063232.html" source="FULLDISC">20070509 Exchange Calendar MODPROPS Denial of Service (CVE-2007-0039)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1593" source="OVAL" sig="1">oval:org.mitre.oval:def:1593</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp1"/>
        <vers num="2003" edition="sp2"/>
        <vers num="2007"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0040" published="2007-07-10" name="CVE-2007-0040" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4, Server 2003 SP1 and SP2, Server 2003 x64 Edition and SP2, and Server 2003 for Itanium-based Systems SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted LDAP request with an unspecified number of "convertible attributes."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-191A.html" source="CERT">TA07-191A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/487905" source="CERT-VN">VU#487905</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/ms07-039.mspx" source="MS" patch="1">MS07-039</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2481" source="VUPEN">ADV-2007-2481</ref>
      <ref url="http://osvdb.org/35960" source="OSVDB">35960</ref>
      <ref url="http://www.securitytracker.com/id?1018355" source="SECTRACK">1018355</ref>
      <ref url="http://www.securityfocus.com/bid/24800" source="BID">24800</ref>
      <ref url="http://www.iss.net/threats/267.html" source="ISS">20070710 Microsoft Windows Active Directory Remote Code Execution</ref>
      <ref url="http://secunia.com/advisories/26002" source="SECUNIA">26002</ref>
      <ref url="http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html" source="HP">SSRT071446</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2012" source="OVAL" sig="1">oval:org.mitre.oval:def:2012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:server"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:itanium"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0041" published="2007-07-10" name="CVE-2007-0041" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer" and unvalidated message lengths, probably a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-191A.html" source="CERT">TA07-191A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/ms07-040.mspx" source="MS" patch="1" adv="1">MS07-040</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34637" source="XF">ms-dotnet-pe-loader-bo(34637)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2482" source="VUPEN" adv="1">ADV-2007-2482</ref>
      <ref url="http://www.securitytracker.com/id?1018356" source="SECTRACK">1018356</ref>
      <ref url="http://www.securityfocus.com/bid/24778" source="BID">24778</ref>
      <ref url="http://secunia.com/advisories/26003" source="SECUNIA" adv="1">26003</ref>
      <ref url="http://osvdb.org/35954" source="OSVDB">35954</ref>
      <ref url="http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html" source="HP">SSRT071446</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2093" source="OVAL" sig="1">oval:org.mitre.oval:def:2093</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0042" published="2007-07-10" name="CVE-2007-0042" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechanisms that try to constrain the final substring of a string, via %00 characters, related to use of %00 as a string terminator within POSIX functions but a data character within .NET strings, aka "Null Byte Termination Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-191A.html" source="CERT">TA07-191A</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2482" source="VUPEN">ADV-2007-2482</ref>
      <ref url="http://www.securitytracker.com/id?1018356" source="SECTRACK">1018356</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/ms07-040.mspx" source="MS">MS07-040</ref>
      <ref url="http://security-assessment.com/files/advisories/2007-07-11_Multiple_.NET_Null_Byte_Injection_Vulnerabilities.pdf" source="MISC">http://security-assessment.com/files/advisories/2007-07-11_Multiple_.NET_Null_Byte_Injection_Vulnerabilities.pdf</ref>
      <ref url="http://secunia.com/advisories/26003" source="SECUNIA" adv="1">26003</ref>
      <ref url="http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html" source="HP">SSRT071446</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2070" source="OVAL" sig="1">oval:org.mitre.oval:def:2070</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0043" published="2007-07-10" name="CVE-2007-0043" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer," probably a buffer overflow, aka ".NET JIT Compiler Vulnerability".</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-191A.html" source="CERT">TA07-191A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/ms07-040.mspx" source="MS" patch="1" adv="1">MS07-040</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34639" source="XF">ms-dotnet-jit-bo(34639)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2482" source="VUPEN" adv="1">ADV-2007-2482</ref>
      <ref url="http://www.securitytracker.com/id?1018356" source="SECTRACK">1018356</ref>
      <ref url="http://www.securityfocus.com/bid/24811" source="BID">24811</ref>
      <ref url="http://secunia.com/advisories/26003" source="SECUNIA" adv="1">26003</ref>
      <ref url="http://osvdb.org/35956" source="OSVDB">35956</ref>
      <ref url="http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html" source="HP">SSRT071446</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1873" source="OVAL" sig="1">oval:org.mitre.oval:def:1873</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0044" published="2007-01-03" name="CVE-2007-0044" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to make unauthorized requests to other web sites via a URL in the (1) FDF, (2) xml, and (3) xfdf AJAX request parameters, following the # (hash) character, aka "Universal CSRF and session riding."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.wisec.it/vulns.php?page=9" source="MISC" patch="1">http://www.wisec.it/vulns.php?page=9</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31266" source="XF">adobe-acrobat-pdf-csrf(31266)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0032" source="VUPEN">ADV-2007-0032</ref>
      <ref url="http://www.securityfocus.com/bid/21858" source="BID">21858</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455801/100/0/threaded" source="BUGTRAQ" adv="1">20070103 Adobe Acrobat Reader Plugin - Multiple Vulnerabilities</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0144.html" source="REDHAT">RHSA-2008:0144</ref>
      <ref url="http://securitytracker.com/id?1017469" source="SECTRACK">1017469</ref>
      <ref url="http://securityreason.com/securityalert/2090" source="SREASON" adv="1">2090</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200701-16.xml" source="GENTOO">GLSA-200701-16</ref>
      <ref url="http://secunia.com/advisories/29065" source="SECUNIA" adv="1">29065</ref>
      <ref url="http://secunia.com/advisories/23882" source="SECUNIA" adv="1">23882</ref>
      <ref url="http://secunia.com/advisories/23812" source="SECUNIA">23812</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10042" source="OVAL">oval:org.mitre.oval:def:10042</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html" source="SUSE">SUSE-SA:2007:011</ref>
      <ref url="http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf" source="MISC">http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="7.0" edition=""/>
        <vers num="7.0" edition=":standard"/>
        <vers num="7.0" edition=":professional"/>
        <vers num="7.0.1" edition=""/>
        <vers num="7.0.1" edition=":standard"/>
        <vers num="7.0.1" edition=":professional"/>
        <vers num="7.0.2" edition=""/>
        <vers num="7.0.2" edition=":professional"/>
        <vers num="7.0.2" edition=":standard"/>
        <vers num="7.0.3" edition=""/>
        <vers num="7.0.3" edition=":professional"/>
        <vers num="7.0.3" edition=":standard"/>
        <vers num="7.0.4" edition=""/>
        <vers num="7.0.4" edition=":professional"/>
        <vers num="7.0.4" edition=":standard"/>
        <vers num="7.0.5" edition=""/>
        <vers num="7.0.5" edition=":professional"/>
        <vers num="7.0.5" edition=":standard"/>
        <vers num="7.0.6" edition=""/>
        <vers num="7.0.6" edition=":standard"/>
        <vers num="7.0.6" edition=":professional"/>
        <vers num="7.0.7" edition=""/>
        <vers num="7.0.7" edition=":professional"/>
        <vers num="7.0.7" edition=":standard"/>
        <vers prev="1" num="7.0.8" edition=""/>
        <vers prev="1" num="7.0.8" edition=":elements"/>
        <vers prev="1" num="7.0.8" edition=":standard"/>
        <vers prev="1" num="7.0.8" edition=":professional"/>
      </prod>
      <prod vendor="adobe" name="acrobat_3d">
        <vers num=""/>
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.5"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.0.5"/>
        <vers num="7.0.6"/>
        <vers num="7.0.7"/>
        <vers prev="1" num="7.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0045" published="2007-01-03" name="CVE-2007-0045" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, for Mozilla Firefox, Microsoft Internet Explorer 6 SP1, Google Chrome, Opera 8.5.4 build 770, and Opera 9.10.8679 on Windows allow remote attackers to inject arbitrary JavaScript and conduct other attacks via a .pdf URL with a javascript: or res: URI with (1) FDF, (2) XML, and (3) XFDF AJAX parameters, or (4) an arbitrarily named name=URI anchor identifier, aka "Universal XSS (UXSS)."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-286B.html" source="CERT">TA09-286B</ref>
      <ref url="http://www.kb.cert.org/vuls/id/815960" source="CERT-VN" adv="1">VU#815960</ref>
      <ref url="http://www.wisec.it/vulns.php?page=9" source="MISC" patch="1">http://www.wisec.it/vulns.php?page=9</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2007-0017.html" source="REDHAT">RHSA-2007:0017</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31271" source="XF">adobe-acrobat-pdf-xss(31271)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2898" source="VUPEN" adv="1">ADV-2009-2898</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0957" source="VUPEN" adv="1">ADV-2007-0957</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0032" source="VUPEN" adv="1">ADV-2007-0032</ref>
      <ref url="http://www.securityfocus.com/bid/21858" source="BID">21858</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455906/100/0/threaded" source="BUGTRAQ">20070104 Universal PDF XSS After Party</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455801/100/0/threaded" source="BUGTRAQ">20070103 Adobe Acrobat Reader Plugin - Multiple Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/455836/100/0/threaded" source="BUGTRAQ">20070103 RE: [WEB SECURITY] Universal XSS with PDF files: highly dangerous</ref>
      <ref url="http://www.securityfocus.com/archive/1/455831/100/0/threaded" source="BUGTRAQ">20070103 Re: [WEB SECURITY] Universal XSS with PDF files: highly dangerous</ref>
      <ref url="http://www.securityfocus.com/archive/1/455800/100/0/threaded" source="BUGTRAQ">20070103 Re: Universal XSS with PDF files: highly dangerous</ref>
      <ref url="http://www.securityfocus.com/archive/1/455790/100/0/threaded" source="BUGTRAQ">20070103 Universal XSS with PDF files: highly dangerous</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0021.html" source="REDHAT">RHSA-2007:0021</ref>
      <ref url="http://www.mozilla.org/security/announce/2007/mfsa2007-02.html" source="CONFIRM">http://www.mozilla.org/security/announce/2007/mfsa2007-02.html</ref>
      <ref url="http://www.gnucitizen.org/blog/universal-pdf-xss-after-party" source="MISC">http://www.gnucitizen.org/blog/universal-pdf-xss-after-party</ref>
      <ref url="http://www.gnucitizen.org/blog/danger-danger-danger/" source="CONFIRM" adv="1">http://www.gnucitizen.org/blog/danger-danger-danger/</ref>
      <ref url="http://www.disenchant.ch/blog/hacking-with-browser-plugins/34" source="MISC">http://www.disenchant.ch/blog/hacking-with-browser-plugins/34</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-15.html" source="CONFIRM">http://www.adobe.com/support/security/bulletins/apsb09-15.html</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb07-01.html" source="CONFIRM">http://www.adobe.com/support/security/bulletins/apsb07-01.html</ref>
      <ref url="http://www.adobe.com/support/security/advisories/apsa07-02.html" source="CONFIRM">http://www.adobe.com/support/security/advisories/apsa07-02.html</ref>
      <ref url="http://www.adobe.com/support/security/advisories/apsa07-01.html" source="CONFIRM" adv="1">http://www.adobe.com/support/security/advisories/apsa07-01.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102847-1" source="SUNALERT">102847</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" source="SLACKWARE">SSA:2007-066-05</ref>
      <ref url="http://securitytracker.com/id?1023007" source="SECTRACK">1023007</ref>
      <ref url="http://securitytracker.com/id?1017469" source="SECTRACK">1017469</ref>
      <ref url="http://securityreason.com/securityalert/2090" source="SREASON">2090</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200701-16.xml" source="GENTOO">GLSA-200701-16</ref>
      <ref url="http://secunia.com/advisories/33754" source="SECUNIA" adv="1">33754</ref>
      <ref url="http://secunia.com/advisories/24533" source="SECUNIA" adv="1">24533</ref>
      <ref url="http://secunia.com/advisories/24457" source="SECUNIA" adv="1">24457</ref>
      <ref url="http://secunia.com/advisories/23882" source="SECUNIA" adv="1">23882</ref>
      <ref url="http://secunia.com/advisories/23877" source="SECUNIA" adv="1">23877</ref>
      <ref url="http://secunia.com/advisories/23812" source="SECUNIA" adv="1">23812</ref>
      <ref url="http://secunia.com/advisories/23691" source="SECUNIA" adv="1">23691</ref>
      <ref url="http://secunia.com/advisories/23483" source="SECUNIA" adv="1">23483</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9693" source="OVAL">oval:org.mitre.oval:def:9693</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6487" source="OVAL">oval:org.mitre.oval:def:6487</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html" source="SUSE">SUSE-SA:2007:011</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">HPSBUX02153</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">HPSBUX02153</ref>
      <ref url="http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="7.0" edition=""/>
        <vers num="7.0" edition=":standard"/>
        <vers num="7.0" edition=":professional"/>
        <vers num="7.0.1" edition=""/>
        <vers num="7.0.1" edition=":standard"/>
        <vers num="7.0.1" edition=":professional"/>
        <vers num="7.0.2" edition=""/>
        <vers num="7.0.2" edition=":professional"/>
        <vers num="7.0.2" edition=":standard"/>
        <vers num="7.0.3" edition=""/>
        <vers num="7.0.3" edition=":professional"/>
        <vers num="7.0.3" edition=":standard"/>
        <vers num="7.0.4" edition=""/>
        <vers num="7.0.4" edition=":professional"/>
        <vers num="7.0.4" edition=":standard"/>
        <vers num="7.0.5" edition=""/>
        <vers num="7.0.5" edition=":professional"/>
        <vers num="7.0.5" edition=":standard"/>
        <vers num="7.0.6" edition=""/>
        <vers num="7.0.6" edition=":standard"/>
        <vers num="7.0.6" edition=":professional"/>
        <vers num="7.0.7" edition=""/>
        <vers num="7.0.7" edition=":professional"/>
        <vers num="7.0.7" edition=":standard"/>
        <vers prev="1" num="7.0.8" edition=""/>
        <vers prev="1" num="7.0.8" edition=":elements"/>
        <vers prev="1" num="7.0.8" edition=":standard"/>
        <vers prev="1" num="7.0.8" edition=":professional"/>
      </prod>
      <prod vendor="adobe" name="acrobat_3d">
        <vers num=""/>
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.5"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.0.5"/>
        <vers num="7.0.6"/>
        <vers num="7.0.7"/>
        <vers prev="1" num="7.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0046" published="2007-01-03" name="CVE-2007-0046" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Double free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0, as used in Mozilla Firefox 1.5.0.7, allows remote attackers to execute arbitrary code by causing an error via a javascript: URI call to document.write in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.wisec.it/vulns.php?page=9" source="MISC" patch="1">http://www.wisec.it/vulns.php?page=9</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0957" source="VUPEN">ADV-2007-0957</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0032" source="VUPEN">ADV-2007-0032</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455801/100/0/threaded" source="BUGTRAQ">20070103 Adobe Acrobat Reader Plugin - Multiple Vulnerabilities</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9684" source="OVAL">oval:org.mitre.oval:def:9684</ref>
      <ref url="http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf" source="MISC">http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2007-0017.html" source="REDHAT">RHSA-2007:0017</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31272" source="XF">adobe-acrobat-msvcrt-code-execution(31272)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0021.html" source="REDHAT">RHSA-2007:0021</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb07-01.html" source="CONFIRM">http://www.adobe.com/support/security/bulletins/apsb07-01.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102847-1" source="SUNALERT">102847</ref>
      <ref url="http://securitytracker.com/id?1017469" source="SECTRACK">1017469</ref>
      <ref url="http://securityreason.com/securityalert/2090" source="SREASON">2090</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200701-16.xml" source="GENTOO">GLSA-200701-16</ref>
      <ref url="http://secunia.com/advisories/24533" source="SECUNIA">24533</ref>
      <ref url="http://secunia.com/advisories/23882" source="SECUNIA">23882</ref>
      <ref url="http://secunia.com/advisories/23877" source="SECUNIA">23877</ref>
      <ref url="http://secunia.com/advisories/23812" source="SECUNIA">23812</ref>
      <ref url="http://secunia.com/advisories/23691" source="SECUNIA">23691</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html" source="SUSE">SUSE-SA:2007:011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers prev="1" num="7.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0047" published="2007-01-03" name="CVE-2007-0047" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">CRLF injection vulnerability in Adobe Acrobat Reader Plugin before 8.0.0, when used with the Microsoft.XMLHTTP ActiveX object in Internet Explorer, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the javascript: URI in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31291" source="XF">adobe-acrobat-xmlhttp-response-splitting(31291)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0032" source="VUPEN">ADV-2007-0032</ref>
      <ref url="http://securitytracker.com/id?1017469" source="SECTRACK">1017469</ref>
      <ref url="http://secunia.com/advisories/23882" source="SECUNIA">23882</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html" source="SUSE">SUSE-SA:2007:011</ref>
      <ref url="http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf" source="MISC">http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers prev="1" num="7.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0048" published="2007-01-03" name="CVE-2007-0048" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, when used with Internet Explorer, Google Chrome, or Opera, allows remote attackers to cause a denial of service (memory consumption) via a long sequence of # (hash) characters appended to a PDF URL, related to a "cross-site scripting issue."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-286B.html" source="CERT">TA09-286B</ref>
      <ref url="http://www.wisec.it/vulns.php?page=9" source="MISC" patch="1" adv="1">http://www.wisec.it/vulns.php?page=9</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31273" source="XF">adobe-acrobat-character-dos(31273)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2898" source="VUPEN">ADV-2009-2898</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0032" source="VUPEN">ADV-2007-0032</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455801/100/0/threaded" source="BUGTRAQ">20070103 Adobe Acrobat Reader Plugin - Multiple Vulnerabilities</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-15.html" source="CONFIRM">http://www.adobe.com/support/security/bulletins/apsb09-15.html</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb07-01.html" source="CONFIRM">http://www.adobe.com/support/security/bulletins/apsb07-01.html</ref>
      <ref url="http://securitytracker.com/id?1023007" source="SECTRACK">1023007</ref>
      <ref url="http://securitytracker.com/id?1017469" source="SECTRACK">1017469</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200701-16.xml" source="GENTOO">GLSA-200701-16</ref>
      <ref url="http://secunia.com/advisories/33754" source="SECUNIA">33754</ref>
      <ref url="http://secunia.com/advisories/23882" source="SECUNIA">23882</ref>
      <ref url="http://secunia.com/advisories/23812" source="SECUNIA">23812</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6348" source="OVAL">oval:org.mitre.oval:def:6348</ref>
      <ref url="http://osvdb.org/31596" source="OSVDB">31596</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html" source="SUSE">SUSE-SA:2007:011</ref>
      <ref url="http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html</ref>
      <ref url="http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf" source="MISC">http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf</ref>
      <ref url="http://securityreason.com/securityalert/2090" source="SREASON">2090</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="7.0" edition=""/>
        <vers num="7.0" edition=":standard"/>
        <vers num="7.0" edition=":professional"/>
        <vers num="7.0.1" edition=""/>
        <vers num="7.0.1" edition=":standard"/>
        <vers num="7.0.1" edition=":professional"/>
        <vers num="7.0.2" edition=""/>
        <vers num="7.0.2" edition=":professional"/>
        <vers num="7.0.2" edition=":standard"/>
        <vers num="7.0.3" edition=""/>
        <vers num="7.0.3" edition=":professional"/>
        <vers num="7.0.3" edition=":standard"/>
        <vers num="7.0.4" edition=""/>
        <vers num="7.0.4" edition=":professional"/>
        <vers num="7.0.4" edition=":standard"/>
        <vers num="7.0.5" edition=""/>
        <vers num="7.0.5" edition=":professional"/>
        <vers num="7.0.5" edition=":standard"/>
        <vers num="7.0.6" edition=""/>
        <vers num="7.0.6" edition=":standard"/>
        <vers num="7.0.6" edition=":professional"/>
        <vers num="7.0.7" edition=""/>
        <vers num="7.0.7" edition=":professional"/>
        <vers num="7.0.7" edition=":standard"/>
        <vers prev="1" num="7.0.8" edition=""/>
        <vers prev="1" num="7.0.8" edition=":elements"/>
        <vers prev="1" num="7.0.8" edition=":standard"/>
        <vers prev="1" num="7.0.8" edition=":professional"/>
      </prod>
      <prod vendor="adobe" name="acrobat_3d">
        <vers num=""/>
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.5"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.0.5"/>
        <vers num="7.0.6"/>
        <vers num="7.0.7"/>
        <vers prev="1" num="7.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0049" published="2007-01-04" name="CVE-2007-0049" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Geckovich TaskTracker Pro 1.5 and earlier allows remote attackers to add administrative or other accounts via an Add action with a modified GroupID in a direct request to Customize.asp.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31235" source="XF">tasktrackerpro-customize-auth-bypass(31235)</ref>
      <ref url="http://www.securityfocus.com/bid/21847" source="BID">21847</ref>
      <ref url="http://secunia.com/advisories/23564" source="SECUNIA" adv="1">23564</ref>
      <ref url="http://osvdb.org/31682" source="OSVDB">31682</ref>
      <ref url="http://milw0rm.com/exploits/3068" source="MILW0RM">3068</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geckovich" name="tasktracker">
        <vers num="1.4"/>
      </prod>
      <prod vendor="geckovich" name="tasktracker_pro">
        <vers prev="1" num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0050" published="2007-01-04" name="CVE-2007-0050" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in index.php in OpenPinboard 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the language parameter.  NOTE: this issue has been disputed by the developer and a third party, since the variable is set before use. CVE analysis suggests that there is a small time window of risk before the installation is complete.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455795/100/0/threaded" source="BUGTRAQ">20070103 OpenPinboard &lt;= Remote File Include</ref>
      <ref url="http://www.securityfocus.com/archive/1/455818/100/0/threaded" source="BUGTRAQ" adv="1">20070103 Re: OpenPinboard &lt;= Remote File Include</ref>
      <ref url="http://osvdb.org/33375" source="OSVDB">33375</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2007-01/0176.html" source="BUGTRAQ">20070106 Re: OpenPinboard &lt;= Remote File Include</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openpinboard" name="openpinboard">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0051" published="2007-01-04" name="CVE-2007-0051" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted attackers to execute arbitrary code via a crafted photocast with format string specifiers in the title of an RSS iPhoto feed.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31281" source="XF">iphoto-xmltitle-format-string(31281)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0057" source="VUPEN" adv="1">ADV-2007-0057</ref>
      <ref url="http://www.securityfocus.com/bid/21871" source="BID">21871</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455968/100/0/threaded" source="BUGTRAQ">20070104 DMA[2007-0104a] - 'iLife iPhoto Photocasing Format String Vulnerability'</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2007-0104a%5D.txt" source="MISC">http://www.digitalmunition.com/DMA[2007-0104a].txt</ref>
      <ref url="http://secunia.com/advisories/23615" source="SECUNIA" adv="1">23615</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-04-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-04-01-2007.html</ref>
      <ref url="http://osvdb.org/31165" source="OSVDB">31165</ref>
      <ref url="http://milw0rm.com/exploits/3080" source="MILW0RM">3080</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar//msg00003.html" source="APPLE">APPLE-SA-2007-03-13</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305215" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305215</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0100.html" source="FULLDISC">20070104 DMA[2007-0104a] - 'iLife iPhoto Photocasing Format String Vulnerability'</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphoto">
        <vers num="6.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0052" published="2007-01-04" name="CVE-2007-0052" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in haberdetay.asp in Vizayn Haber allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0015" source="VUPEN">ADV-2007-0015</ref>
      <ref url="http://www.securityfocus.com/bid/21836" source="BID">21836</ref>
      <ref url="http://secunia.com/advisories/23576" source="SECUNIA" adv="1">23576</ref>
      <ref url="http://osvdb.org/31518" source="OSVDB">31518</ref>
      <ref url="http://milw0rm.com/exploits/3061" source="MILW0RM">3061</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31213" source="XF">vicayn-haberdetay-sql-injection(31213)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vizayn_haber" name="vizayn_haber">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0053" published="2007-01-04" name="CVE-2007-0053" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in detail.asp in ASP SiteWare autoDealer 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the iPro parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0016" source="VUPEN">ADV-2007-0016</ref>
      <ref url="http://www.securityfocus.com/bid/21833" source="BID">21833</ref>
      <ref url="http://secunia.com/advisories/23572" source="SECUNIA" adv="1">23572</ref>
      <ref url="http://osvdb.org/32539" source="OSVDB">32539</ref>
      <ref url="http://milw0rm.com/exploits/3062" source="MILW0RM">3062</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31219" source="XF">autodealer-detail-sql-injection(31219)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asp_siteware" name="autodealer">
        <vers prev="1" num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0054" published="2007-01-04" name="CVE-2007-0054" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in gbrowse.php in Belchior Foundry vCard PRO allows remote attackers to inject arbitrary web script or HTML via the sortby parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21844" source="BID">21844</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455615/100/0/threaded" source="BUGTRAQ">20070101 vBulletin vCard PRO XSS</ref>
      <ref url="http://osvdb.org/33359" source="OSVDB">33359</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31182" source="XF">vcard-gbrowse-xss(31182)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="belchior_foundry" name="vcard_pro">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0055" published="2007-01-04" name="CVE-2007-0055" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in formbankcgi.exe/AbfrageForm in Formbankserver 1.9 allows remote attackers to read arbitrary files via directory traversal sequences in the Name parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0012" source="VUPEN">ADV-2007-0012</ref>
      <ref url="http://secunia.com/advisories/23539" source="SECUNIA">23539</ref>
      <ref url="http://osvdb.org/32545" source="OSVDB">32545</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31214" source="XF">formbankserver-name-directory-traversal(31214)</ref>
      <ref url="http://milw0rm.com/exploits/3063" source="MILW0RM">3063</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fersch" name="formbankserver">
        <vers num="1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0056" published="2007-01-04" name="CVE-2007-0056" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe 4.5 and AShop Administration Panel allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to (a) ashop/catalogue.php and (b) ashop/basket.php, the (2) exp parameter to ashop/catalogue.php, the (3) searchstring parameter to (c) ashop/search.php, the (4) checkout and (5) action parameters to (d) ashop/shipping.php, the cat parameter to (f) cart-path/admin/editcatalogue.php, and the (7) resultpage parameter to (g) cart-path/admin/salesadmin.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0028" source="VUPEN">ADV-2007-0028</ref>
      <ref url="http://www.securityfocus.com/bid/21845" source="BID">21845</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455629/100/0/threaded" source="BUGTRAQ">20070101 AShop Shopping Cart Multiple XSS Vulnerabilities</ref>
      <ref url="http://osvdb.org/32558" source="OSVDB">32558</ref>
      <ref url="http://osvdb.org/32557" source="OSVDB">32557</ref>
      <ref url="http://osvdb.org/32556" source="OSVDB">32556</ref>
      <ref url="http://osvdb.org/32555" source="OSVDB">32555</ref>
      <ref url="http://osvdb.org/32554" source="OSVDB">32554</ref>
      <ref url="http://osvdb.org/32553" source="OSVDB">32553</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31178" source="XF">ashop-multiple-scripts-xss(31178)</ref>
      <ref url="http://securityreason.com/securityalert/2091" source="SREASON">2091</ref>
      <ref url="http://secunia.com/advisories/23547" source="SECUNIA">23547</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ashopsoftware" name="ashop_administration_panel">
        <vers num=""/>
      </prod>
      <prod vendor="ashopsoftware" name="ashop_deluxe">
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0057" published="2007-01-04" name="CVE-2007-0057" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Cisco Clean Access (CCA) 3.6.x through 3.6.4.2 and 4.0.x through 4.0.3.2 does not properly configure or allow modification of a shared secret authentication key, which causes all devices to have the same shared sercet and allows remote attackers to gain unauthorized access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070103-CleanAccess.shtml" source="CISCO" patch="1" adv="1">20070103 Multiple Vulnerabilities in Cisco Clean Access</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0030" source="VUPEN">ADV-2007-0030</ref>
      <ref url="http://osvdb.org/32578" source="OSVDB">32578</ref>
      <ref url="http://securitytracker.com/id?1017465" source="SECTRACK">1017465</ref>
      <ref url="http://secunia.com/advisories/23617" source="SECUNIA">23617</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="clean_access">
        <vers prev="1" num="3.5.9"/>
        <vers prev="1" num="3.6.1.1"/>
        <vers prev="1" num="4.0.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0058" published="2007-01-04" name="CVE-2007-0058" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco Clean Access (CCA) 3.5.x through 3.5.9 and 3.6.x through 3.6.1.1 on the Clean Access Manager (CAM) allows remote attackers to bypass authentication and download arbitrary manual database backups by guessing the snapshot filename using brute force, then making a direct request for the file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0030" source="VUPEN">ADV-2007-0030</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070103-CleanAccess.shtml" source="CISCO">20070103 Multiple Vulnerabilities in Cisco Clean Access</ref>
      <ref url="http://securitytracker.com/id?1017465" source="SECTRACK">1017465</ref>
      <ref url="http://secunia.com/advisories/23556" source="SECUNIA">23556</ref>
      <ref url="http://www.osvdb.org/32579" source="OSVDB">32579</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="clean_access">
        <vers prev="1" num="3.5.9"/>
        <vers prev="1" num="3.6.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0059" published="2007-01-04" name="CVE-2007-0059" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attackers to execute arbitrary code and list filesystem contents via a QuickTime movie (.MOV) with an HREF Track (HREFTrack) that contains an automatic action tag with a local URI, which is executed in a local zone during preview, as exploited by a MySpace worm.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/304064" source="CERT-VN">VU#304064</ref>
      <ref url="http://www.gnucitizen.org/blog/backdooring-quicktime-movies/" source="MISC" adv="1">http://www.gnucitizen.org/blog/backdooring-quicktime-movies/</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-03-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-03-01-2007.html</ref>
      <ref url="http://osvdb.org/31164" source="OSVDB">31164</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html" source="APPLE">APPLE-SA-2007-03-05</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305149" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305149</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3"/>
        <vers prev="1" num="7.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0060" published="2007-07-25" name="CVE-2007-0060" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the Message Queuing Server (Cam.exe) in CA (formerly Computer Associates) Message Queuing (CAM / CAFT) software before 1.11 Build 54_4 on Windows and NetWare, as used in CA Advantage Data Transport, eTrust Admin, certain BrightStor products, certain CleverPath products, and certain Unicenter products, allows remote attackers to execute arbitrary code via a crafted message to TCP port 3104.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32234" source="XF">systems-management-bo(32234)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2638" source="VUPEN">ADV-2007-2638</ref>
      <ref url="http://www.securityfocus.com/bid/25051" source="BID">25051</ref>
      <ref url="http://www.iss.net/threats/272.html" source="ISS">20070724 CA Message Queuing Server (Cam.exe) Overflow</ref>
      <ref url="http://supportconnectw.ca.com/public/dto_transportit/infodocs/camsgquevul-secnot.asp" source="CONFIRM">http://supportconnectw.ca.com/public/dto_transportit/infodocs/camsgquevul-secnot.asp</ref>
      <ref url="http://secunia.com/advisories/26190" source="SECUNIA" adv="1">26190</ref>
      <ref url="http://www.securitytracker.com/id?1018449" source="SECTRACK">1018449</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/474602/100/0/threaded" source="BUGTRAQ">20070725 [CAID 35527]: CA Message Queuing (CAM / CAFT) Buffer Overflow Vulnerability</ref>
      <ref url="http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=149809" source="CONFIRM">http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=149809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="advantage_data_transport">
        <vers num="3.0"/>
      </prod>
      <prod vendor="ca" name="brightstor_portal">
        <vers num="11.1"/>
      </prod>
      <prod vendor="ca" name="brightstor_san_manager">
        <vers num="11.1"/>
        <vers num="11.5"/>
      </prod>
      <prod vendor="ca" name="cleverpath_aion">
        <vers num="10.0"/>
      </prod>
      <prod vendor="ca" name="cleverpath_ecm">
        <vers num="3.5"/>
      </prod>
      <prod vendor="ca" name="cleverpath_olap">
        <vers num="5.1"/>
      </prod>
      <prod vendor="ca" name="cleverpath_predictive_analysis_server">
        <vers num="2.0"/>
        <vers num="3.0"/>
      </prod>
      <prod vendor="ca" name="etrust_admin">
        <vers num="2.1"/>
        <vers num="2.4"/>
        <vers num="2.7"/>
        <vers num="2.9"/>
        <vers num="8.0"/>
        <vers num="8.1"/>
      </prod>
      <prod vendor="ca" name="unicenter_application_performance_monitor">
        <vers num="3.0"/>
        <vers num="3.5"/>
      </prod>
      <prod vendor="ca" name="unicenter_asset_management">
        <vers num="3.1"/>
        <vers num="3.2" edition="sp1"/>
        <vers num="3.2" edition="sp2"/>
        <vers num="4.0" edition="sp1"/>
      </prod>
      <prod vendor="ca" name="unicenter_data_transport_option">
        <vers num="2.0"/>
      </prod>
      <prod vendor="ca" name="unicenter_enterprise_job_manager">
        <vers num="1.0" edition="sp1"/>
        <vers num="1.0" edition="sp2"/>
      </prod>
      <prod vendor="ca" name="unicenter_jasmine">
        <vers num="3.0"/>
      </prod>
      <prod vendor="ca" name="unicenter_management">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":lotus_notes_domino"/>
        <vers num="4.0" edition=":microsoft_exchange"/>
        <vers num="4.1" edition=""/>
        <vers num="4.1" edition=":microsoft_exchange"/>
        <vers num="5.0" edition=""/>
        <vers num="5.0" edition=":web_servers"/>
        <vers num="5.0.1" edition=""/>
        <vers num="5.0.1" edition=":web_servers"/>
      </prod>
      <prod vendor="ca" name="unicenter_network_and_systems_management">
        <vers num="3.0"/>
        <vers num="3.1"/>
      </prod>
      <prod vendor="ca" name="unicenter_nsm_wireless_network_management_option">
        <vers num="3.0"/>
      </prod>
      <prod vendor="ca" name="unicenter_remote_control">
        <vers num="6.0" edition="sp1"/>
      </prod>
      <prod vendor="ca" name="unicenter_service_level_management">
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.5"/>
      </prod>
      <prod vendor="ca" name="unicenter_software_delivery">
        <vers num="3.0"/>
        <vers num="3.1" edition="sp1"/>
        <vers num="3.1" edition="sp2"/>
        <vers num="4.0" edition="sp1"/>
      </prod>
      <prod vendor="ca" name="unicenter_tng">
        <vers num="2.1"/>
        <vers num="2.2" edition=""/>
        <vers num="2.2" edition=":"/>
        <vers num="2.2" edition="::jp"/>
        <vers num="2.4"/>
        <vers num="2.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0061" published="2007-09-21" name="CVE-2007-0061" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a malformed packet that triggers "corrupt stack memory."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33101" source="XF" patch="1">dhcp-malformed-packet-bo(33101)</ref>
      <ref url="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html" source="CONFIRM" patch="1">http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html</ref>
      <ref url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html" source="CONFIRM" patch="1">http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html</ref>
      <ref url="http://www.vmware.com/support/server/doc/releasenotes_server.html" source="CONFIRM" patch="1">http://www.vmware.com/support/server/doc/releasenotes_server.html</ref>
      <ref url="http://www.vmware.com/support/player2/doc/releasenotes_player2.html" source="CONFIRM" patch="1">http://www.vmware.com/support/player2/doc/releasenotes_player2.html</ref>
      <ref url="http://www.vmware.com/support/player/doc/releasenotes_player.html" source="CONFIRM" patch="1">http://www.vmware.com/support/player/doc/releasenotes_player.html</ref>
      <ref url="http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html" source="CONFIRM" patch="1">http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html</ref>
      <ref url="http://www.vmware.com/support/ace/doc/releasenotes_ace.html" source="CONFIRM" patch="1">http://www.vmware.com/support/ace/doc/releasenotes_ace.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3229" source="VUPEN">ADV-2007-3229</ref>
      <ref url="http://www.securityfocus.com/bid/25729" source="BID">25729</ref>
      <ref url="http://www.iss.net/threats/275.html" source="ISS" adv="1">20070919 VMWare DHCP Server Remote Code Execution Vulnerabilities</ref>
      <ref url="http://www.ubuntu.com/usn/usn-543-1" source="UBUNTU">USN-543-1</ref>
      <ref url="http://www.securitytracker.com/id?1018717" source="SECTRACK">1018717</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200711-23.xml" source="GENTOO">GLSA-200711-23</ref>
      <ref url="http://secunia.com/advisories/27706" source="SECUNIA">27706</ref>
      <ref url="http://secunia.com/advisories/27694" source="SECUNIA">27694</ref>
      <ref url="http://secunia.com/advisories/26890" source="SECUNIA">26890</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html" source="FULLDISC">20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="ace">
        <vers num="1.0"/>
        <vers prev="1" num="1.0.3_build_54075"/>
        <vers prev="1" num="2.0.1_build_55017"/>
      </prod>
      <prod vendor="vmware" name="player">
        <vers prev="1" num="1.0"/>
        <vers prev="1" num="1.0.5_build_56455"/>
        <vers prev="1" num="2.0.1_build_55017"/>
      </prod>
      <prod vendor="vmware" name="server">
        <vers prev="1" num="1.0.4_build_56528"/>
      </prod>
      <prod vendor="vmware" name="workstation">
        <vers prev="1" num="5.5"/>
        <vers prev="1" num="5.5.1"/>
        <vers prev="1" num="5.5.3"/>
        <vers prev="1" num="5.5.3_build_34685"/>
        <vers prev="1" num="5.5.5_build_56455"/>
        <vers prev="1" num="6.0"/>
        <vers prev="1" num="6.0.1_build_55017"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0062" published="2007-09-21" name="CVE-2007-0062" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in the ISC dhcpd 3.0.x before 3.0.7 and 3.1.x before 3.1.1; and the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528; allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a malformed DHCP packet with a large dhcp-max-message-size that triggers a stack-based buffer overflow, related to servers configured to send many DHCP options to clients.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33102" source="XF" patch="1">dhcp-param-overflow(33102)</ref>
      <ref url="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html" source="CONFIRM" patch="1">http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html</ref>
      <ref url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html" source="CONFIRM" patch="1">http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html</ref>
      <ref url="http://www.vmware.com/support/server/doc/releasenotes_server.html" source="CONFIRM" patch="1">http://www.vmware.com/support/server/doc/releasenotes_server.html</ref>
      <ref url="http://www.vmware.com/support/player2/doc/releasenotes_player2.html" source="CONFIRM" patch="1">http://www.vmware.com/support/player2/doc/releasenotes_player2.html</ref>
      <ref url="http://www.vmware.com/support/player/doc/releasenotes_player.html" source="CONFIRM" patch="1">http://www.vmware.com/support/player/doc/releasenotes_player.html</ref>
      <ref url="http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html" source="CONFIRM" patch="1">http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html</ref>
      <ref url="http://www.vmware.com/support/ace/doc/releasenotes_ace.html" source="CONFIRM" patch="1">http://www.vmware.com/support/ace/doc/releasenotes_ace.html</ref>
      <ref url="http://www.securityfocus.com/bid/25729" source="BID" patch="1">25729</ref>
      <ref url="http://www.iss.net/threats/275.html" source="ISS" patch="1">20070919 VMWare DHCP Server Remote Code Execution Vulnerabilities</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=339561" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=339561</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3229" source="VUPEN" adv="1">ADV-2007-3229</ref>
      <ref url="http://www.ubuntu.com/usn/usn-543-1" source="UBUNTU">USN-543-1</ref>
      <ref url="http://www.securitytracker.com/id?1018717" source="SECTRACK">1018717</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501759/100/0/threaded" source="BUGTRAQ">20090312 rPSA-2009-0041-1 dhclient dhcp libdhcp4client</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:153" source="MANDRIVA">MDVSA-2009:153</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0041" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0041</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200808-05.xml" source="GENTOO">GLSA-200808-05</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200711-23.xml" source="GENTOO">GLSA-200711-23</ref>
      <ref url="http://secunia.com/advisories/34263" source="SECUNIA" adv="1">34263</ref>
      <ref url="http://secunia.com/advisories/31396" source="SECUNIA" adv="1">31396</ref>
      <ref url="http://secunia.com/advisories/27706" source="SECUNIA" adv="1">27706</ref>
      <ref url="http://secunia.com/advisories/27694" source="SECUNIA" adv="1">27694</ref>
      <ref url="http://secunia.com/advisories/26890" source="SECUNIA" adv="1">26890</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html" source="SUSE">SUSE-SR:2009:005</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html" source="FULLDISC">20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=227135" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=227135</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="ace">
        <vers num="1.0.3"/>
        <vers num="2.0"/>
      </prod>
      <prod vendor="vmware" name="player">
        <vers num="1.0.4"/>
        <vers num="2.0"/>
      </prod>
      <prod vendor="vmware" name="server">
        <vers num="1.0.3"/>
      </prod>
      <prod vendor="vmware" name="vmware_workstation">
        <vers num="6.0.1"/>
      </prod>
      <prod vendor="vmware" name="workstation">
        <vers num="3.4"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.5.2"/>
        <vers num="5.5.0_build_13124"/>
        <vers num="5.5.1"/>
        <vers num="5.5.1_build_19175"/>
        <vers num="5.5.3_build_34685"/>
        <vers num="5.5.3_build_42958"/>
        <vers num="5.5.4"/>
        <vers num="5.5.4_build_44386"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0063" published="2007-09-21" name="CVE-2007-0063" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a malformed DHCP packet that triggers a stack-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33103" source="XF" patch="1">dhcp-param-underflow(33103)</ref>
      <ref url="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html" source="CONFIRM" patch="1">http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html</ref>
      <ref url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html" source="CONFIRM" patch="1">http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html</ref>
      <ref url="http://www.vmware.com/support/server/doc/releasenotes_server.html" source="CONFIRM" patch="1">http://www.vmware.com/support/server/doc/releasenotes_server.html</ref>
      <ref url="http://www.vmware.com/support/player2/doc/releasenotes_player2.html" source="CONFIRM" patch="1">http://www.vmware.com/support/player2/doc/releasenotes_player2.html</ref>
      <ref url="http://www.vmware.com/support/player/doc/releasenotes_player.html" source="CONFIRM" patch="1">http://www.vmware.com/support/player/doc/releasenotes_player.html</ref>
      <ref url="http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html" source="CONFIRM" patch="1">http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html</ref>
      <ref url="http://www.vmware.com/support/ace/doc/releasenotes_ace.html" source="CONFIRM" patch="1">http://www.vmware.com/support/ace/doc/releasenotes_ace.html</ref>
      <ref url="http://www.securityfocus.com/bid/25729" source="BID" patch="1">25729</ref>
      <ref url="http://www.iss.net/threats/275.html" source="ISS" patch="1" adv="1">20070919 VMWare DHCP Server Remote Code Execution Vulnerabilities</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3229" source="VUPEN">ADV-2007-3229</ref>
      <ref url="http://www.ubuntu.com/usn/usn-543-1" source="UBUNTU">USN-543-1</ref>
      <ref url="http://www.securitytracker.com/id?1018717" source="SECTRACK">1018717</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200711-23.xml" source="GENTOO">GLSA-200711-23</ref>
      <ref url="http://secunia.com/advisories/27706" source="SECUNIA">27706</ref>
      <ref url="http://secunia.com/advisories/27694" source="SECUNIA">27694</ref>
      <ref url="http://secunia.com/advisories/26890" source="SECUNIA">26890</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html" source="FULLDISC">20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="ace">
        <vers num="1.0"/>
        <vers prev="1" num="1.0.3_build_54075"/>
        <vers prev="1" num="2.0.1_build_55017"/>
      </prod>
      <prod vendor="vmware" name="esx_server">
        <vers num="2.0.2"/>
        <vers num="2.1.3"/>
        <vers num="2.5.3"/>
        <vers num="2.5.4"/>
        <vers num="3.0.0"/>
        <vers num="3.0.1"/>
      </prod>
      <prod vendor="vmware" name="player">
        <vers prev="1" num="1.0"/>
        <vers prev="1" num="1.0.5_build_56455"/>
        <vers prev="1" num="2.0.1_build_55017"/>
      </prod>
      <prod vendor="vmware" name="server">
        <vers prev="1" num="1.0.4_build_56528"/>
      </prod>
      <prod vendor="vmware" name="workstation">
        <vers prev="1" num="5.5"/>
        <vers prev="1" num="5.5.1"/>
        <vers prev="1" num="5.5.3"/>
        <vers prev="1" num="5.5.3_build_34685"/>
        <vers prev="1" num="5.5.5_build_56455"/>
        <vers prev="1" num="6.0"/>
        <vers prev="1" num="6.0.1_build_55017"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0064" published="2007-12-11" name="CVE-2007-0064" modified="2011-03-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Windows Media Format Runtime 7.1, 9, 9.5, 9.5 x64 Edition, 11, and Windows Media Services 9.1 for Microsoft Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-345A.html" source="CERT">TA07-345A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/319385" source="CERT-VN">VU#319385</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-068.mspx" source="MS" patch="1" adv="1">MS07-068</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/4183" source="VUPEN" adv="1">ADV-2007-4183</ref>
      <ref url="http://www.securitytracker.com/id?1019074" source="SECTRACK">1019074</ref>
      <ref url="http://www.securityfocus.com/bid/26776" source="BID">26776</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485268/100/0/threaded" source="HP">SSRT071506</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485268/100/0/threaded" source="HP">SSRT071506</ref>
      <ref url="http://secunia.com/advisories/28034" source="SECUNIA" adv="1">28034</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3622" source="OVAL" sig="1">oval:org.mitre.oval:def:3622</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_format_runtime">
        <vers num="11"/>
        <vers num="7.1"/>
        <vers num="9"/>
        <vers num="9.5" edition=""/>
        <vers num="9.5" edition=":x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_media_services">
        <vers num="9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0065" published="2008-02-12" name="CVE-2007-0065" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, Office 2004 for Mac, and Visual basic 6.0 SP6 allows remote attackers to execute arbitrary code via a crafted script request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" source="CERT">TA08-043C</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-008.mspx" source="MS" patch="1">MS08-008</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0510/references" source="VUPEN">ADV-2008-0510</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">SSRT080016</ref>
      <ref url="http://www.securitytracker.com/id?1019373" source="SECTRACK">1019373</ref>
      <ref url="http://www.securityfocus.com/bid/27661" source="BID">27661</ref>
      <ref url="http://secunia.com/advisories/28902" source="SECUNIA">28902</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">SSRT080016</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5388" source="OVAL" sig="1">oval:org.mitre.oval:def:5388</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="" edition=":mac+os"/>
      </prod>
      <prod vendor="microsoft" name="visual_basic">
        <vers num="6.0" edition="sp6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0066" published="2008-01-08" name="CVE-2007-0066" modified="2011-03-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router advertisement ICMP packets that trigger an out-of-bounds read, aka "Windows Kernel TCP/IP/ICMP Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-008A.html" source="CERT">TA08-008A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-001.mspx" source="MS" patch="1" adv="1">MS08-001</ref>
      <ref url="http://secunia.com/advisories/28297" source="SECUNIA" patch="1" adv="1">28297</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39254" source="XF">win-tcpip-icmp-dos(39254)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0069" source="VUPEN" adv="1">ADV-2008-0069</ref>
      <ref url="http://www.securityfocus.com/bid/27139" source="BID">27139</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486317/100/0/threaded" source="HP">SSRT080003</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486317/100/0/threaded" source="HP">HPSBST02304</ref>
      <ref url="http://www.iss.net/threats/282.html" source="ISS">20070108 Multiple (3) Microsoft Windows TCP/IP Remote Code Execution and DoS Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1019166" source="SECTRACK">1019166</ref>
      <ref url="http://blogs.technet.com/swi/archive/2008/01/08/ms08-001-part-2-the-case-of-the-moderate-icmp-mitigations.aspx" source="MISC">http://blogs.technet.com/swi/archive/2008/01/08/ms08-001-part-2-the-case-of-the-moderate-icmp-mitigations.aspx</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5271" source="OVAL" sig="1">oval:org.mitre.oval:def:5271</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="home_server">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="small_business_server">
        <vers num="2003" edition=""/>
        <vers num="2003" edition=":sp1"/>
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:itanium"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:standard"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2"/>
        <vers num="-" edition="sp1"/>
        <vers num="-" edition="sp1:x64"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0067" published="2007-06-06" name="CVE-2007-0067" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Lotus Domino Web Server 6.0, 6.5.x before 6.5.6, and 7.0.x before 7.0.3 allows remote attackers to cause a denial of service (daemon crash) via requests for URLs that reference certain files.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/24307" source="BID" patch="1">24307</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21257251" source="CONFIRM" patch="1">http://www-1.ibm.com/support/docview.wss?uid=swg21257251</ref>
      <ref url="http://secunia.com/advisories/25542" source="SECUNIA" patch="1" adv="1">25542</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34689" source="XF">domino-unspecified-dos(34689)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2046" source="VUPEN">ADV-2007-2046</ref>
      <ref url="http://osvdb.org/35766" source="OSVDB">35766</ref>
      <ref url="http://www.securitytracker.com/id?1018189" source="SECTRACK">1018189</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino_web_server">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.2_cf2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.5"/>
        <vers num="6.5.0"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4" edition=""/>
        <vers num="6.5.4" edition=":fp1"/>
        <vers num="6.5.4" edition=":fp2"/>
        <vers num="6.5.5" edition=""/>
        <vers num="6.5.5" edition=":fp1"/>
        <vers num="6.5.5" edition=":fp2"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2" edition=""/>
        <vers num="7.0.2" edition=":fp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0068" published="2007-06-06" name="CVE-2007-0068" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">IBM Lotus Domino 7.0.x before 7.0.3 does not revalidate the signature on a signed scheduled agent after the agent is modified, which allows remote authenticated users to gain privileges via a modified agent in a server database.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/2063" source="VUPEN">ADV-2007-2063</ref>
      <ref url="http://www.securityfocus.com/bid/24322" source="BID">24322</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21258784" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg21258784</ref>
      <ref url="http://secunia.com/advisories/25520" source="SECUNIA" adv="1">25520</ref>
      <ref url="http://osvdb.org/35765" source="OSVDB">35765</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34718" source="XF">domino-signature-privilege-escalation(34718)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0069" published="2008-01-08" name="CVE-2007-0069" modified="2011-03-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the kernel in Microsoft Windows XP SP2, Server 2003, and Vista allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via crafted (1) IGMPv3 and (2) MLDv2 packets that trigger memory corruption, aka "Windows Kernel TCP/IP/IGMPv3 and MLDv2 Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-008A.html" source="CERT">TA08-008A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/115083" source="CERT-VN">VU#115083</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-001.mspx" source="MS" patch="1" adv="1">MS08-001</ref>
      <ref url="http://secunia.com/advisories/28297" source="SECUNIA" patch="1" adv="1">28297</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39453" source="XF">win-ssm-mld-bo(39453)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39452" source="XF">win-ssm-igmp-bo(39452)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0069" source="VUPEN" adv="1">ADV-2008-0069</ref>
      <ref url="http://www.securityfocus.com/bid/27100" source="BID">27100</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486317/100/0/threaded" source="HP">HPSBST02304</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486317/100/0/threaded" source="HP">HPSBST02304</ref>
      <ref url="http://www.iss.net/threats/282.html" source="ISS">20070108 Multiple (3) Microsoft Windows TCP/IP Remote Code Execution and DoS Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1019166" source="SECTRACK">1019166</ref>
      <ref url="http://blogs.technet.com/swi/archive/2008/01/08/ms08-001-part-3-the-case-of-the-igmp-network-critical.aspx" source="MISC">http://blogs.technet.com/swi/archive/2008/01/08/ms08-001-part-3-the-case-of-the-igmp-network-critical.aspx</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5370" source="OVAL" sig="1">oval:org.mitre.oval:def:5370</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0071" published="2008-04-09" name="CVE-2007-0071" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file with a negative Scene Count value, which passes a signed comparison, is used as an offset of a NULL pointer, and triggers a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-150A.html" source="CERT">TA08-150A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-149A.html" source="CERT">TA08-149A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-100A.html" source="CERT">TA08-100A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/395473" source="CERT-VN">VU#395473</ref>
      <ref url="http://www.kb.cert.org/vuls/id/159523" source="CERT-VN">VU#159523</ref>
      <ref url="http://xforce.iss.net/getrecord.jsp?id=37277" source="XF">multimedia-file-integer-overflow(37277)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-08-032/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-08-032/</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1724/references" source="VUPEN" adv="1">ADV-2008-1724</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1697" source="VUPEN" adv="1">ADV-2008-1697</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1662/references" source="VUPEN" adv="1">ADV-2008-1662</ref>
      <ref url="http://www.securitytracker.com/id?1019811" source="SECTRACK">1019811</ref>
      <ref url="http://www.securityfocus.com/bid/29386" source="BID">29386</ref>
      <ref url="http://www.securityfocus.com/bid/28695" source="BID">28695</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0221.html" source="REDHAT">RHSA-2008:0221</ref>
      <ref url="http://www.osvdb.org/44282" source="OSVDB">44282</ref>
      <ref url="http://www.matasano.com/log/1032/this-new-vulnerability-dowds-inhuman-flash-exploit/" source="MISC">http://www.matasano.com/log/1032/this-new-vulnerability-dowds-inhuman-flash-exploit/</ref>
      <ref url="http://www.iss.net/threats/289.html" source="ISS">20080408 Adobe Flash Player Invalid Pointer Vulnerability</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200804-21.xml" source="GENTOO">GLSA-200804-21</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb08-11.html" source="CONFIRM" adv="1">http://www.adobe.com/support/security/bulletins/apsb08-11.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-238305-1" source="SUNALERT">238305</ref>
      <ref url="http://secunia.com/advisories/30507" source="SECUNIA" adv="1">30507</ref>
      <ref url="http://secunia.com/advisories/30430" source="SECUNIA" adv="1">30430</ref>
      <ref url="http://secunia.com/advisories/30404" source="SECUNIA" adv="1">30404</ref>
      <ref url="http://secunia.com/advisories/29865" source="SECUNIA" adv="1">29865</ref>
      <ref url="http://secunia.com/advisories/29763" source="SECUNIA" adv="1">29763</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10379" source="OVAL">oval:org.mitre.oval:def:10379</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00006.html" source="SUSE">SUSE-SA:2008:022</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008//May/msg00001.html" source="APPLE">APPLE-SA-2008-05-28</ref>
      <ref url="http://isc.sans.org/diary.html?storyid=4465" source="MISC">http://isc.sans.org/diary.html?storyid=4465</ref>
      <ref url="http://documents.iss.net/whitepapers/IBM_X-Force_WP_final.pdf" source="MISC">http://documents.iss.net/whitepapers/IBM_X-Force_WP_final.pdf</ref>
      <ref url="http://blogs.adobe.com/psirt/2008/05/potential_flash_player_issue.html" source="MISC">http://blogs.adobe.com/psirt/2008/05/potential_flash_player_issue.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="air">
        <vers num="1.0"/>
      </prod>
      <prod vendor="adobe" name="flash_player">
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.25"/>
        <vers num="7.0.63"/>
        <vers num="7.1"/>
        <vers num="7.1.1"/>
        <vers num="7.2"/>
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":pro"/>
        <vers num="8.0" edition=":basic"/>
        <vers num="8.0.24.0"/>
        <vers num="8.0.34.0"/>
        <vers num="8.0.35.0"/>
        <vers prev="1" num="8.0.39.0"/>
        <vers num="9"/>
        <vers num="9.0.112.0"/>
        <vers num="9.0.114.0"/>
        <vers prev="1" num="9.0.115.0"/>
        <vers num="9.0.16"/>
        <vers num="9.0.20"/>
        <vers num="9.0.20.0"/>
        <vers num="9.0.28.0"/>
        <vers num="9.0.31"/>
        <vers num="9.0.31.0"/>
        <vers num="9.0.45.0"/>
        <vers num="9.0.47.0"/>
        <vers num="9.0.48.0"/>
      </prod>
      <prod vendor="adobe" name="flex">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0072" published="2008-11-17" name="CVE-2007-0072" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a read operation over RPC.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/768681" source="CERT-VN">VU#768681</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/38760" source="XF" adv="1">application-rpc-read-bo(38760)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/3127" source="VUPEN">ADV-2008-3127</ref>
      <ref url="http://www.securityfocus.com/bid/32261" source="BID">32261</ref>
      <ref url="http://www.iss.net/threats/309.html" source="ISS">20081111 Trend Micro ServerProtect [PROCEDURE NAME REDACTED] Heap Overflows (3)</ref>
      <ref url="http://secunia.com/advisories/32618" source="SECUNIA" adv="1">32618</ref>
      <ref url="http://blogs.iss.net/archive/trend.html" source="MISC">http://blogs.iss.net/archive/trend.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="serverprotect">
        <vers num="5.58"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0073" published="2008-11-17" name="CVE-2007-0073" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a file read operation over RPC.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/768681" source="CERT-VN">VU#768681</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39050" source="XF">application-rpc-file-read-bo(39050)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/3127" source="VUPEN">ADV-2008-3127</ref>
      <ref url="http://www.securityfocus.com/bid/32261" source="BID">32261</ref>
      <ref url="http://www.iss.net/threats/309.html" source="ISS">20081111 Trend Micro ServerProtect [PROCEDURE NAME REDACTED] Heap Overflows (3)</ref>
      <ref url="http://secunia.com/advisories/32618" source="SECUNIA" adv="1">32618</ref>
      <ref url="http://blogs.iss.net/archive/trend.html" source="MISC">http://blogs.iss.net/archive/trend.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="serverprotect">
        <vers num="5.58"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0074" published="2008-11-17" name="CVE-2007-0074" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a folder read operation over RPC.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/768681" source="CERT-VN">VU#768681</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39051" source="XF">application-rpc-folder-read-bo(39051)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/3127" source="VUPEN">ADV-2008-3127</ref>
      <ref url="http://www.securityfocus.com/bid/32261" source="BID">32261</ref>
      <ref url="http://www.iss.net/threats/309.html" source="ISS">20081111 Trend Micro ServerProtect [PROCEDURE NAME REDACTED] Heap Overflows (3)</ref>
      <ref url="http://secunia.com/advisories/32618" source="SECUNIA" adv="1">32618</ref>
      <ref url="http://blogs.iss.net/archive/trend.html" source="MISC">http://blogs.iss.net/archive/trend.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="serverprotect">
        <vers num="5.58"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0075" published="2007-01-05" name="CVE-2007-0075" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">AspBB stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user passwords via a direct request for db/aspbb.mdb.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31230" source="XF">aspbb-aspbb-info-disclosure(31230)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455683/100/0/threaded" source="BUGTRAQ">20070102 AspBB Remote Password Disclosure</ref>
      <ref url="http://www.aria-security.com/forum/showthread.php?t=82" source="MISC">http://www.aria-security.com/forum/showthread.php?t=82</ref>
      <ref url="http://osvdb.org/33364" source="OSVDB">33364</ref>
      <ref url="http://securityreason.com/securityalert/2100" source="SREASON">2100</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aspbb" name="aspbb">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0076" published="2007-01-05" name="CVE-2007-0076" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Openforum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user passwords via a direct request for openforum.mdb.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31209" source="XF">openforum-openforum-password-disclosure(31209)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455684/100/0/threaded" source="BUGTRAQ">20070102 Openforum Remote password Disclosure</ref>
      <ref url="http://www.aria-security.com/forum/showthread.php?t=80" source="MISC">http://www.aria-security.com/forum/showthread.php?t=80</ref>
      <ref url="http://osvdb.org/33366" source="OSVDB">33366</ref>
      <ref url="http://securityreason.com/securityalert/2099" source="SREASON">2099</ref>
    </refs>
    <vuln_soft>
      <prod vendor="2enetworx" name="openforum">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0077" published="2007-01-05" name="CVE-2007-0077" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">lblog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for a certain file in admin/db/newFolder/.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31229" source="XF">lblog-newfolder-information-disclosure(31229)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455681/100/0/threaded" source="BUGTRAQ">20070102 lblog Remote Password Disclosure</ref>
      <ref url="http://www.aria-security.com/forum/showthread.php?t=79" source="MISC">http://www.aria-security.com/forum/showthread.php?t=79</ref>
      <ref url="http://securitytracker.com/id?1017462" source="SECTRACK">1017462</ref>
      <ref url="http://osvdb.org/33367" source="OSVDB">33367</ref>
      <ref url="http://securityreason.com/securityalert/2098" source="SREASON">2098</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lblog" name="lblog">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0078" published="2007-01-05" name="CVE-2007-0078" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BattleBlog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/blankmaster.mdb.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31224" source="XF">battleblog-blankmaster-info-disclosure(31224)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455614/100/0/threaded" source="BUGTRAQ">20070101 BattleBlog Database Download Vulnerability</ref>
      <ref url="http://www.aria-security.com/forum/showthread.php?t=76" source="MISC">http://www.aria-security.com/forum/showthread.php?t=76</ref>
      <ref url="http://osvdb.org/33360" source="OSVDB">33360</ref>
      <ref url="http://securityreason.com/securityalert/2097" source="SREASON">2097</ref>
    </refs>
    <vuln_soft>
      <prod vendor="battleblog" name="battleblog">
        <vers num="1.0d"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0079" published="2007-01-05" name="CVE-2007-0079" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">rblog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) data/admin.mdb or (2) data/rblog.mdb.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31200" source="XF">rblog-database-info-disclosure(31200)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455626/100/0/threaded" source="BUGTRAQ">20070101 rblog Database Download Vulnerability</ref>
      <ref url="http://www.aria-security.com/forum/showthread.php?t=77" source="MISC">http://www.aria-security.com/forum/showthread.php?t=77</ref>
      <ref url="http://secunia.com/advisories/23538" source="SECUNIA">23538</ref>
      <ref url="http://osvdb.org/32572" source="OSVDB">32572</ref>
      <ref url="http://securityreason.com/securityalert/2102" source="SREASON">2102</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rblog" name="rblog">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0080" published="2007-01-05" name="CVE-2007-0080" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.7" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">** DISPUTED **  Buffer overflow in the SMB_Connect_Server function in FreeRadius 1.1.3 and earlier allows attackers to execute arbitrary code related to the server desthost field of an SMB_Handle_Type instance.  NOTE: the impact of this issue has been disputed by a reliable third party and the vendor, who states that exploitation is limited "only to local administrators who have write access to the server configuration files."  CVE concurs with the dispute.</descript>
      <descript source="nvd">A buffer overflow in the SMB_Connect_Server function in FreeRADIUS 1.1.4 and earlier allows attackers to execute arbitrary code related to the server desthost field of an SMB_Handle_Type instance.  This issue can not be exploited remotely, and can only be exploited by administrators who have write access to the server configuration files.</descript>
    </desc>
    <impacts>
      <impact source="nvd">-- Official Vendor Statement from the FreeRADIUS Server project

This issue is not a security vulnerability.  The exploit is available only to local administrators who have write access to the server configuration files.  As such, this issue has no security impact on any system running FreeRADIUS.

-- Official Vendor Statement from the FreeRADIUS Server project
</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31248" source="XF">freeradius-smbconnectserver-bo(31248)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455678/100/0/threaded" source="BUGTRAQ" adv="1">20070102 FreeRadius 1.1.3 SMB_Handle_Type SMB_Connect_Server arbitrary code execution</ref>
      <ref url="http://www.securityfocus.com/archive/1/455812/100/0/threaded" source="BUGTRAQ">20070103 Re: FreeRadius 1.1.3 SMB_Handle_Type SMB_Connect_Server arbitrary code execution</ref>
      <ref url="http://www.freeradius.org/security.html" source="MISC">http://www.freeradius.org/security.html</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-February/001304.html" source="VIM">20070211 FreeRADIUS dispute of CVE-2007-0080</ref>
      <ref url="http://securitytracker.com/id?1017463" source="SECTRACK">1017463</ref>
      <ref url="http://osvdb.org/32082" source="OSVDB">32082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freeradius" name="freeradius">
        <vers prev="1" num="1.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0081" published="2007-01-05" name="CVE-2007-0081" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Sunbelt Kerio Personal Firewall (SKPF) 4.3.268 and 4.3.246, and possibly other versions allows local users to provide a Trojan horse iphlpapi.dll to SKPF by placing it in the installation directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31232" source="XF">kerio-directory-code-execution(31232)</ref>
      <ref url="http://www.securityfocus.com/bid/21828" source="BID">21828</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455624/100/0/threaded" source="BUGTRAQ" adv="1">20070101 Kerio Fake 'iphlpapi' DLL injection Vulnerability</ref>
      <ref url="http://www.matousec.com/info/advisories/Kerio-Fake-iphlpapi-DLL-injection.php" source="MISC" adv="1">http://www.matousec.com/info/advisories/Kerio-Fake-iphlpapi-DLL-injection.php</ref>
      <ref url="http://www.osvdb.org/33356" source="OSVDB">33356</ref>
      <ref url="http://securityreason.com/securityalert/2095" source="SREASON">2095</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sunbelt" name="sunbelt_kerio_personal_firewall">
        <vers num="4.3.246"/>
        <vers num="4.3.268"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0082" published="2007-01-05" name="CVE-2007-0082" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">users_adm/start1.php in IMGallery 2.5 and earlier does not properly handle files with multiple extensions, which allows remote authenticated users to upload and execute arbitrary PHP scripts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31237" source="XF" adv="1">imgallery-start1-file-upload(31237)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0010" source="VUPEN">ADV-2007-0010</ref>
      <ref url="http://www.securityfocus.com/bid/21827" source="BID" adv="1">21827</ref>
      <ref url="http://milw0rm.com/exploits/3049" source="MILW0RM">3049</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imgallery" name="imgallery">
        <vers num="2.4"/>
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0083" published="2007-01-05" name="CVE-2007-0083" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Nuked Klan 1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in a getURL statement in a .swf file, as demonstrated by "Remote Cookie Disclosure."  NOTE: it could be argued that this is an issue in Shockwave instead of Nuked Klan.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21850" source="BID">21850</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455726/100/0/threaded" source="BUGTRAQ">20070102 Nuked Klan &lt;= 1.7 Remote Cookie Disclosure Exploit</ref>
      <ref url="http://osvdb.org/33368" source="OSVDB">33368</ref>
      <ref url="http://securityreason.com/securityalert/2101" source="SREASON">2101</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nuked-klan" name="nuked-klan">
        <vers num="1.2"/>
        <vers num="1.2_beta"/>
        <vers num="1.3"/>
        <vers num="1.3_beta"/>
        <vers num="1.4"/>
        <vers num="1.5"/>
        <vers num="1.5_sp2"/>
        <vers num="1.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0084" published="2007-01-05" name="CVE-2007-0084" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.7" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">** DISPUTED **  Buffer overflow in the Windows NT Message Compiler (MC) 1.00.5239 on Microsoft Windows XP allows local users to gain privileges via a long MC-filename.  NOTE: this issue has been disputed by a reliable third party who states that the compiler is not a privileged program, so privilege boundaries cannot be crossed.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455729/100/0/threaded" source="BUGTRAQ" adv="1">20070102 Windows NT Message Compiler 1.00.5239 arbitrary code execution</ref>
      <ref url="http://www.securityfocus.com/archive/1/455789/100/0/threaded" source="BUGTRAQ" adv="1">20070103 Re: Windows NT Message Compiler 1.00.5239 arbitrary code execution</ref>
      <ref url="http://osvdb.org/37817" source="OSVDB">37817</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="message_compiler">
        <vers num="1.00.5239"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0085" published="2007-01-05" name="CVE-2007-0085" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:S/C:C/I:C/A:C)" CVSS_score="6.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.5" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in sys/dev/pci/vga_pci.c in the VGA graphics driver for wscons in OpenBSD 3.9 and 4.0, when the kernel is compiled with the PCIAGP option and a non-AGP device is being used, allows local users to gain privileges via unspecified vectors, possibly related to agp_ioctl NULL pointer reference.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.openbsd.org/errata39.html#agp" source="OPENBSD" patch="1" adv="1">[3.9] 017: SECURITY FIX: January 3, 2007</ref>
      <ref url="http://www.openbsd.org/errata.html#agp" source="OPENBSD" patch="1" adv="1">[4.0] 007: SECURITY FIX: January 3, 2007</ref>
      <ref url="http://securitytracker.com/id?1017468" source="SECTRACK" patch="1" adv="1">1017468</ref>
      <ref url="http://secunia.com/advisories/23608" source="SECUNIA" patch="1" adv="1">23608</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31276" source="XF">openbsd-vga-privilege-escalation(31276)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0043" source="VUPEN">ADV-2007-0043</ref>
      <ref url="http://marc.theaimsgroup.com/?l=openbsd-cvs&amp;m=116785923301416&amp;w=2" source="MLIST">[openbsd-cvs] 20070103 CVS: cvs.openbsd.org: www</ref>
      <ref url="http://marc.theaimsgroup.com/?l=openbsd-cvs&amp;m=116781980706409&amp;w=2" source="MLIST">[openbsd-cvs] 20070103 Re: CVS: cvs.openbsd.org: src</ref>
      <ref url="http://ilja.netric.org/files/Unusual%20bugs%2023c3.pdf" source="MISC" adv="1">http://ilja.netric.org/files/Unusual%20bugs%2023c3.pdf</ref>
      <ref url="http://www.osvdb.org/32574" source="OSVDB">32574</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.9"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0086" published="2007-01-05" name="CVE-2007-0086" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">** DISPUTED **  The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment.  NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455833/100/0/threaded" source="BUGTRAQ">20070103 a cheesy Apache / IIS DoS vuln (+a question)</ref>
      <ref url="http://www.securityfocus.com/archive/1/455920/100/0/threaded" source="BUGTRAQ">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</ref>
      <ref url="http://www.securityfocus.com/archive/1/455882/100/0/threaded" source="BUGTRAQ">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</ref>
      <ref url="http://www.securityfocus.com/archive/1/455879/100/0/threaded" source="BUGTRAQ">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</ref>
      <ref url="http://osvdb.org/33456" source="OSVDB">33456</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0087" published="2007-01-05" name="CVE-2007-0087" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">** DISPUTED **  Microsoft Internet Information Services (IIS), when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment.  NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455833/100/0/threaded" source="BUGTRAQ">20070103 a cheesy Apache / IIS DoS vuln (+a question)</ref>
      <ref url="http://www.securityfocus.com/archive/1/455920/100/0/threaded" source="BUGTRAQ">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</ref>
      <ref url="http://www.securityfocus.com/archive/1/455882/100/0/threaded" source="BUGTRAQ">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</ref>
      <ref url="http://www.securityfocus.com/archive/1/455879/100/0/threaded" source="BUGTRAQ">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</ref>
      <ref url="http://osvdb.org/33457" source="OSVDB">33457</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0088" published="2007-01-05" name="CVE-2007-0088" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in openmedia allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) src parameter to page.php or the (2) format parameter to search_form.php.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31258" source="XF">openmedia-page-directory-traversal(31258)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455786/100/0/threaded" source="BUGTRAQ">20070102 openmedia local read file</ref>
      <ref url="http://osvdb.org/33371" source="OSVDB">33371</ref>
      <ref url="http://osvdb.org/33370" source="OSVDB">33370</ref>
      <ref url="http://securityreason.com/securityalert/2103" source="SREASON">2103</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openmedia" name="openmedia">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0089" published="2007-01-05" name="CVE-2007-0089" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">jgbbs stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/bbs.mdb.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455832/100/0/threaded" source="BUGTRAQ">20070103 jgbbs</ref>
      <ref url="http://osvdb.org/33376" source="OSVDB">33376</ref>
      <ref url="http://aria-security.com/forum/showthread.php?t=87" source="MISC">http://aria-security.com/forum/showthread.php?t=87</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31274" source="XF">jgbbs-bbs-information-disclosure(31274)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jgbbs" name="jgbbs">
        <vers num="3.0" edition="beta_1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0090" published="2007-01-05" name="CVE-2007-0090" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">WineGlass stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/data.mdb.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0037" source="VUPEN">ADV-2007-0037</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455807/100/0/threaded" source="BUGTRAQ">20070103 WineGlass "data.mdb" Remote Password Disclosure</ref>
      <ref url="http://osvdb.org/32575" source="OSVDB">32575</ref>
      <ref url="http://aria-security.com/forum/showthread.php?p=112" source="MISC">http://aria-security.com/forum/showthread.php?p=112</ref>
      <ref url="http://secunia.com/advisories/23594" source="SECUNIA">23594</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fermentigrafici" name="wineglass">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0091" published="2007-01-05" name="CVE-2007-0091" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">newsCMSlite stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for newsCMS.mdb.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31222" source="XF">newscmslite-newscms-info-disclosure(31222)</ref>
      <ref url="http://osvdb.org/37548" source="OSVDB">37548</ref>
      <ref url="http://milw0rm.com/exploits/3066" source="MILW0RM">3066</ref>
    </refs>
    <vuln_soft>
      <prod vendor="katy_whitton_web_development" name="newscmslite">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0092" published="2007-01-05" name="CVE-2007-0092" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in productdetail.asp in E-SMARTCART 1.0 allows remote attackers to execute arbitrary SQL commands via the product_id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0036" source="VUPEN">ADV-2007-0036</ref>
      <ref url="http://secunia.com/advisories/23610" source="SECUNIA" adv="1">23610</ref>
      <ref url="http://osvdb.org/31679" source="OSVDB">31679</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31243" source="XF">esmartcart-productdetail-sql-injection(31243)</ref>
      <ref url="http://milw0rm.com/exploits/3074" source="MILW0RM">3074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e-smart_cart" name="e-smart_cart">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0093" published="2007-01-05" name="CVE-2007-0093" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in page.php in Simple Web Content Management System allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31261" source="XF">swcms-page-sql-injection(31261)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0040" source="VUPEN">ADV-2007-0040</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455814/100/0/threaded" source="BUGTRAQ">20070103 Simple Web Content Management System SQL Injection Exploit</ref>
      <ref url="http://secunia.com/advisories/23590" source="SECUNIA">23590</ref>
      <ref url="http://osvdb.org/31657" source="OSVDB">31657</ref>
      <ref url="http://milw0rm.com/exploits/3076" source="MILW0RM">3076</ref>
      <ref url="http://acid-root.new.fr/poc/18070102.txt" source="MISC">http://acid-root.new.fr/poc/18070102.txt</ref>
      <ref url="http://securityreason.com/securityalert/2106" source="SREASON">2106</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cms-center" name="simple_web_cms">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0094" published="2007-01-05" name="CVE-2007-0094" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Sven Moderow GuestBook 0.3a stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for (1) gbook97.mdb or (2) gbook.mdb in ~db/.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455788/100/0/threaded" source="BUGTRAQ">20070103 GuestBook v0.3a Remote Password Disclosure</ref>
      <ref url="http://osvdb.org/33363" source="OSVDB">33363</ref>
      <ref url="http://aria-security.com/forum/showthread.php?p=114" source="MISC">http://aria-security.com/forum/showthread.php?p=114</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31245" source="XF">guestbook-gbook-information-disclosure(31245)</ref>
      <ref url="http://securityreason.com/securityalert/2105" source="SREASON">2105</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sven_moderow" name="sven_moderow_guestbook">
        <vers num="0.3a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0095" published="2007-01-05" name="CVE-2007-0095" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">phpMyAdmin 2.9.1.1 allows remote attackers to obtain sensitive information via a direct request for themes/darkblue_orange/layout.inc.php, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31223" source="XF">phpmyadmin-darkblueorange-path-disclosure(31223)</ref>
      <ref url="http://osvdb.org/33257" source="OSVDB">33257</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051544.html" source="FULLDISC">20070102 Inforamtion Discloser Vulnerabilities in  phpMyAdmin</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0034.html" source="FULLDISC">20070102 Inforamtion Discloser Vulnerabilities in "phpMyAdmin"</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:199" source="MANDRIVA">MDKSA-2007:199</ref>
      <ref url="http://securityreason.com/securityalert/2104" source="SREASON">2104</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="2.9.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0096" published="2007-01-05" name="CVE-2007-0096" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CarbonCommunities stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for DataBase/Carbon2.4d.mdb.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31253" source="XF">carboncommunities-carbon2-info-disclosure(31253)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0038" source="VUPEN">ADV-2007-0038</ref>
      <ref url="http://osvdb.org/37549" source="OSVDB">37549</ref>
      <ref url="http://aria-security.com/forum/showthread.php?t=85" source="MISC">http://aria-security.com/forum/showthread.php?t=85</ref>
    </refs>
    <vuln_soft>
      <prod vendor="carbon_communities" name="carbon_communities">
        <vers prev="1" num="2.4d"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0097" published="2007-01-05" name="CVE-2007-0097" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the (1) LoadTree and (2) ReadHeader functions in PAISO.DLL 1.7.3.0 (1.7.3 beta) in ConeXware PowerArchiver 2006 9.64.02 allow user-assisted attackers to execute arbitrary code via a crafted ISO file containing a file within several nested directories.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://vuln.sg/powarc964-en.html" source="MISC" patch="1" adv="1">http://vuln.sg/powarc964-en.html</ref>
      <ref url="http://secunia.com/advisories/23559" source="SECUNIA" patch="1" adv="1">23559</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0041" source="VUPEN">ADV-2007-0041</ref>
      <ref url="http://osvdb.org/32576" source="OSVDB">32576</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=116791509125050&amp;w=2" source="FULLDISC" adv="1">20070104 [vuln.sg] PowerArchiver PAISO.DLL Buffer Overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31263" source="XF">powerarchiver-loadtree-readheader-bo(31263)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455892/100/0/threaded" source="BUGTRAQ">20070104 [vuln.sg] PowerArchiver PAISO.DLL Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="conexware" name="powerarchiver_2006">
        <vers num="9.64.02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0098" published="2007-01-05" name="CVE-2007-0098" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in language.php in VerliAdmin 0.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by language.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0035" source="VUPEN">ADV-2007-0035</ref>
      <ref url="http://osvdb.org/32352" source="OSVDB">32352</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31241" source="XF">verliadmin-language-file-include(31241)</ref>
      <ref url="http://milw0rm.com/exploits/3075" source="MILW0RM">3075</ref>
    </refs>
    <vuln_soft>
      <prod vendor="verliadmin" name="verliadmin">
        <vers prev="1" num="0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0099" published="2007-01-08" name="CVE-2007-0099" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via many nested tags in an XML document in an IFRAME, when synchronous document rendering is frequently disrupted with asynchronous events, as demonstrated using a JavaScript timer, which can trigger NULL pointer dereferences or memory corruption, aka "MSXML Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <race/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-316A.html" source="CERT">TA08-316A</ref>
      <ref url="http://www.securityfocus.com/bid/21872" source="BID" patch="1">21872</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS08-069.mspx" source="MS" patch="1" adv="1">MS08-069</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/3111" source="VUPEN" adv="1">ADV-2008-3111</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456343/100/0/threaded" source="BUGTRAQ">20070104 Re: RE: [Full-disclosure] Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455986/100/0/threaded" source="BUGTRAQ">20070104 RE: [Full-disclosure] Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455965/100/0/threaded" source="BUGTRAQ">20070104 Concurrency strikes MSIE (potentially exploitable msxml3 flaws)</ref>
      <ref url="http://securitytracker.com/id?1021164" source="SECTRACK">1021164</ref>
      <ref url="http://secunia.com/advisories/23655" source="SECUNIA" adv="1">23655</ref>
      <ref url="http://seclists.org/fulldisclosure/2007/Jan/0110.html" source="FULLDISC">20070104 Concurrency strikes MSIE (potentially exploitable msxml3 flaws)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5793" source="OVAL">oval:org.mitre.oval:def:5793</ref>
      <ref url="http://osvdb.org/32627" source="OSVDB">32627</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=122703006921213&amp;w=2" source="HP">SSRT080164</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=122703006921213&amp;w=2" source="HP">HPSBST02386</ref>
      <ref url="http://isc.sans.org/diary.php?storyid=2004" source="MISC">http://isc.sans.org/diary.php?storyid=2004</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0113.html" source="FULLDISC">20070104 Re: Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="6"/>
      </prod>
      <prod vendor="microsoft" name="xml_core_services">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0100" published="2007-01-08" name="CVE-2007-0100" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Perforce client does not restrict the set of files that it overwrites upon receiving a request from the server, which allows remote attackers to overwrite arbitrary files by modifying the client config file on the server, or by operating a malicious server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455977/100/0/threaded" source="BUGTRAQ">20070104 Perforce client: security hole by design</ref>
      <ref url="http://osvdb.org/33369" source="OSVDB">33369</ref>
    </refs>
    <vuln_soft>
      <prod vendor="perforce" name="perforce_client">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0101" published="2007-01-08" name="CVE-2007-0101" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in SPINE allows remote attackers to perform unauthorized actions as administrators via unspecified vectors.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://spine.sourceforge.net/changelog.html" source="MISC" patch="1">http://spine.sourceforge.net/changelog.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31283" source="XF">spine-unspecified-csrf(31283)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0042" source="VUPEN">ADV-2007-0042</ref>
      <ref url="http://secunia.com/advisories/23537" source="SECUNIA" adv="1">23537</ref>
      <ref url="http://osvdb.org/32577" source="OSVDB">32577</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spine" name="spine">
        <vers prev="1" num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0102" published="2007-01-08" name="CVE-2007-0102" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The Adobe PDF specification 1.3, as implemented by Apple Mac OS X Preview, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://www.securityfocus.com/bid/21910" source="BID" patch="1">21910</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31364" source="XF">multiple-vendor-pdf-code-execution(31364)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://www.securitytracker.com/id?1017749" source="SECTRACK">1017749</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-06-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-06-01-2007.html</ref>
      <ref url="http://osvdb.org/31221" source="OSVDB">31221</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="preview">
        <vers num="3.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0103" published="2007-01-08" name="CVE-2007-0103" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The Adobe PDF specification 1.3, as implemented by Adobe Acrobat before 8.0.0, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31364" source="XF">multiple-vendor-pdf-code-execution(31364)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://www.securitytracker.com/id?1017749" source="SECTRACK">1017749</ref>
      <ref url="http://www.securityfocus.com/bid/21910" source="BID">21910</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-06-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-06-01-2007.html</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers prev="1" num="7.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0104" published="2007-01-08" name="CVE-2007-0104" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="https://issues.rpath.com/browse/RPL-964" source="CONFIRM">https://issues.rpath.com/browse/RPL-964</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31364" source="XF">multiple-vendor-pdf-code-execution(31364)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN" adv="1">ADV-2007-0930</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0244" source="VUPEN" adv="1">ADV-2007-0244</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0212" source="VUPEN" adv="1">ADV-2007-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0203" source="VUPEN" adv="1">ADV-2007-0203</ref>
      <ref url="http://www.ubuntu.com/usn/usn-410-2" source="UBUNTU">USN-410-2</ref>
      <ref url="http://www.ubuntu.com/usn/usn-410-1" source="UBUNTU">USN-410-1</ref>
      <ref url="http://www.securitytracker.com/id?1017749" source="SECTRACK">1017749</ref>
      <ref url="http://www.securityfocus.com/bid/21910" source="BID">21910</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457055/100/0/threaded" source="BUGTRAQ">20070116 [KDE Security Advisory] kpdf/kword/xpdf denial of service vulnerability</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_3_sr.html" source="SUSE">SUSE-SR:2007:003</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:024" source="MANDRIVA">MDKSA-2007:024</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:022" source="MANDRIVA">MDKSA-2007:022</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:021" source="MANDRIVA">MDKSA-2007:021</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:020" source="MANDRIVA">MDKSA-2007:020</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:019" source="MANDRIVA">MDKSA-2007:019</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:018" source="MANDRIVA">MDKSA-2007:018</ref>
      <ref url="http://www.kde.org/info/security/advisory-20070115-1.txt" source="CONFIRM">http://www.kde.org/info/security/advisory-20070115-1.txt</ref>
      <ref url="http://support.novell.com/techcenter/psdb/44d7cb9b669d58e0ce5aa5d7ab2c7c53.html" source="CONFIRM">http://support.novell.com/techcenter/psdb/44d7cb9b669d58e0ce5aa5d7ab2c7c53.html</ref>
      <ref url="http://securitytracker.com/id?1017514" source="SECTRACK">1017514</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA" adv="1">24479</ref>
      <ref url="http://secunia.com/advisories/24204" source="SECUNIA" adv="1">24204</ref>
      <ref url="http://secunia.com/advisories/23876" source="SECUNIA" adv="1">23876</ref>
      <ref url="http://secunia.com/advisories/23844" source="SECUNIA" adv="1">23844</ref>
      <ref url="http://secunia.com/advisories/23839" source="SECUNIA" adv="1">23839</ref>
      <ref url="http://secunia.com/advisories/23815" source="SECUNIA" adv="1">23815</ref>
      <ref url="http://secunia.com/advisories/23813" source="SECUNIA" adv="1">23813</ref>
      <ref url="http://secunia.com/advisories/23808" source="SECUNIA" adv="1">23808</ref>
      <ref url="http://secunia.com/advisories/23799" source="SECUNIA" adv="1">23799</ref>
      <ref url="http://secunia.com/advisories/23791" source="SECUNIA">23791</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-06-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-06-01-2007.html</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xpdf" name="xpdf">
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1_pl1"/>
        <vers num="3.0.1_pl2"/>
        <vers num="3.0_pl2"/>
      </prod>
      <prod vendor="kde" name="kde">
        <vers num="3.2"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="3.2.3"/>
        <vers num="3.3"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.4"/>
        <vers num="3.4.1"/>
        <vers num="3.4.2"/>
        <vers num="3.4.3"/>
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0105" published="2007-01-08" name="CVE-2007-0105" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the CSAdmin service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows remote attackers to execute arbitrary code via a crafted HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/744249" source="CERT-VN">VU#744249</ref>
      <ref url="http://secunia.com/advisories/23629" source="SECUNIA" patch="1" adv="1">23629</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31323" source="XF">cisco-acs-csadmin-bo(31323)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0068" source="VUPEN">ADV-2007-0068</ref>
      <ref url="http://www.securityfocus.com/bid/21900" source="BID">21900</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070105-csacs.shtml" source="CISCO" adv="1">20070105 Multiple Vulnerabilities in Cisco Secure Access Control Server</ref>
      <ref url="http://securitytracker.com/id?1017475" source="SECTRACK">1017475</ref>
      <ref url="http://www.osvdb.org/32642" source="OSVDB">32642</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="secure_access_control_server">
        <vers prev="1" num="4.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0106" published="2007-01-08" name="CVE-2007-0106" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the CSRF protection scheme in WordPress before 2.0.6 allows remote attackers to inject arbitrary web script or HTML via a CSRF attack with an invalid token and quote characters or HTML tags in URL variable names, which are not properly handled when WordPress generates a new link to verify the request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21893" source="BID" patch="1" adv="1">21893</ref>
      <ref url="http://wordpress.org/development/2007/01/wordpress-206/" source="CONFIRM" patch="1" adv="1">http://wordpress.org/development/2007/01/wordpress-206/</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0061" source="VUPEN">ADV-2007-0061</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456048/100/0/threaded" source="BUGTRAQ" adv="1">20070105 Advisory 01/2007: WordPress CSRF Protection XSS Vulnerability</ref>
      <ref url="http://www.hardened-php.net/advisory_012007.140.html" source="MISC" adv="1">http://www.hardened-php.net/advisory_012007.140.html</ref>
      <ref url="http://secunia.com/advisories/23595" source="SECUNIA" adv="1">23595</ref>
      <ref url="http://osvdb.org/33397" source="OSVDB">33397</ref>
      <ref url="http://securityreason.com/securityalert/2114" source="SREASON">2114</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0107" published="2007-01-08" name="CVE-2007-0107" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query, which allows remote attackers to bypass SQL injection protection schemes and execute arbitrary SQL commands via multibyte charsets, as demonstrated using UTF-7.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that the "mbstring" extension be enabled.
This vulnerability is addressed in the following product release:
WordPress, WordPress, 2.0.6</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31297" source="XF" patch="1">wordpress-mbstring-security-bypass(31297)</ref>
      <ref url="http://www.securityfocus.com/bid/21907" source="BID" patch="1">21907</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456049/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20070105 Advisory 02/2007: WordPress Trackback Charset Decoding SQL Injection Vulnerability</ref>
      <ref url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.005.html" source="OPENPKG" patch="1" adv="1">OpenPKG-SA-2007.005</ref>
      <ref url="http://www.hardened-php.net/advisory_022007.141.html" source="MISC" patch="1" adv="1">http://www.hardened-php.net/advisory_022007.141.html</ref>
      <ref url="http://wordpress.org/development/2007/01/wordpress-206/" source="CONFIRM" patch="1">http://wordpress.org/development/2007/01/wordpress-206/</ref>
      <ref url="http://secunia.com/advisories/23595" source="SECUNIA" patch="1" adv="1">23595</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0061" source="VUPEN">ADV-2007-0061</ref>
      <ref url="http://osvdb.org/31579" source="OSVDB">31579</ref>
      <ref url="http://securityreason.com/securityalert/2112" source="SREASON">2112</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200701-10.xml" source="GENTOO">GLSA-200701-10</ref>
      <ref url="http://secunia.com/advisories/23741" source="SECUNIA">23741</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers prev="1" num="2.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0108" published="2007-01-08" name="CVE-2007-0108" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">nwgina.dll in Novell Client 4.91 SP3 for Windows 2000/XP/2003 does not delete user profiles during a Terminal Service or Citrix session, which allows remote authenticated users to invoke alternate user profiles.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31343" source="XF">novell-profile-security-bypass(31343)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0064" source="VUPEN">ADV-2007-0064</ref>
      <ref url="http://www.securityfocus.com/bid/21886" source="BID">21886</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974970.htm" source="CONFIRM" adv="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974970.htm</ref>
      <ref url="http://securitytracker.com/id?1017471" source="SECTRACK">1017471</ref>
      <ref url="http://secunia.com/advisories/23619" source="SECUNIA" adv="1">23619</ref>
      <ref url="http://osvdb.org/31358" source="OSVDB">31358</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="client">
        <vers num="4.91" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0109" published="2007-01-08" name="CVE-2007-0109" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">wp-login.php in WordPress 2.0.5 and earlier displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31262" source="XF" adv="1">wordpress-account-enumeration(31262)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0062" source="VUPEN">ADV-2007-0062</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455927/100/0/threaded" source="BUGTRAQ" adv="1">20070103 Wordpress &lt;= 2.x dictionnary &amp; Bruteforce attack</ref>
      <ref url="http://secunia.com/advisories/23621" source="SECUNIA" adv="1">23621</ref>
      <ref url="http://osvdb.org/31577" source="OSVDB">31577</ref>
      <ref url="http://securityreason.com/securityalert/2113" source="SREASON">2113</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200701-10.xml" source="GENTOO">GLSA-200701-10</ref>
      <ref url="http://secunia.com/advisories/23741" source="SECUNIA">23741</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0110" published="2007-01-08" name="CVE-2007-0110" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in nidp/idff/sso in Novell Access Manager Identity Server before 3.0.0-1013 allows remote attackers to inject arbitrary web script or HTML via the IssueInstant parameter, which is not properly handled in the resulting error message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://secure-support.novell.com/KanisaPlatform/Publishing/143/3615264_f.SAL_Public.html" source="CONFIRM" adv="1">https://secure-support.novell.com/KanisaPlatform/Publishing/143/3615264_f.SAL_Public.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0073" source="VUPEN">ADV-2007-0073</ref>
      <ref url="http://www.securityfocus.com/bid/21921" source="BID">21921</ref>
      <ref url="http://secunia.com/advisories/23654" source="SECUNIA">23654</ref>
      <ref url="http://osvdb.org/31359" source="OSVDB">31359</ref>
      <ref url="http://securitytracker.com/id?1017483" source="SECTRACK">1017483</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="access_manager_identity_server">
        <vers prev="1" num="3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0111" published="2007-01-08" name="CVE-2007-0111" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in Resco Photo Viewer for PocketPC 4.11 and 6.01, as used in mobile devices running Windows Mobile 5.0, 2003, and 2003SE, allows remote attackers to execute arbitrary code via a crafted PNG image.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0072" source="VUPEN">ADV-2007-0072</ref>
      <ref url="http://www.trendmicro.com/vinfo/secadvisories/default6.asp?VName=Vulnerability+in+Resco+Photo+Viewer+6%2E01+Enabling+Code+Injection+and+Arbitrary+Code+Execution" source="MISC" adv="1">http://www.trendmicro.com/vinfo/secadvisories/default6.asp?VName=Vulnerability+in+Resco+Photo+Viewer+6%2E01+Enabling+Code+Injection+and+Arbitrary+Code+Execution</ref>
      <ref url="http://www.securityfocus.com/bid/21920" source="BID" adv="1">21920</ref>
      <ref url="http://secunia.com/advisories/23658" source="SECUNIA" adv="1">23658</ref>
      <ref url="http://osvdb.org/32644" source="OSVDB">32644</ref>
      <ref url="http://blog.trendmicro.com/flaw-in-3rd-party-app-weakens-windows-mobile/" source="MISC" adv="1">http://blog.trendmicro.com/flaw-in-3rd-party-app-weakens-windows-mobile/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="resco" name="photo_viewer">
        <vers num="4.11"/>
        <vers num="6.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0112" published="2007-01-08" name="CVE-2007-0112" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in cats.asp in createauction allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31356" source="XF">createauction-cats-sql-injection(31356)</ref>
      <ref url="http://www.securityfocus.com/bid/21929" source="BID">21929</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456272/100/0/threaded" source="BUGTRAQ">20070107 createauction (cats.asp) Remote SQL Injection Vulnerability</ref>
      <ref url="http://osvdb.org/33406" source="OSVDB">33406</ref>
      <ref url="http://securityreason.com/securityalert/2111" source="SREASON">2111</ref>
    </refs>
    <vuln_soft>
      <prod vendor="createauction" name="createauction">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0113" published="2007-01-08" name="CVE-2007-0113" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:C)" CVSS_score="6.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.0" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in Packeteer PacketShaper PacketWise 8.x allows remote authenticated users to cause a denial of service (reset or reboot) via (1) a long traffic class argument to the "class show" command or (2) a long POLICY parameter value in clastree.htm.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31357" source="XF">packetshaper-argument-dos(31357)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0098" source="VUPEN">ADV-2007-0098</ref>
      <ref url="http://www.securityfocus.com/bid/21933" source="BID" adv="1">21933</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456267/100/0/threaded" source="BUGTRAQ" adv="1">20070108 Packeteer PacketWise CLI overflow DoS</ref>
      <ref url="http://secunia.com/advisories/23685" source="SECUNIA" adv="1">23685</ref>
      <ref url="http://osvdb.org/31656" source="OSVDB">31656</ref>
      <ref url="http://securityreason.com/securityalert/2110" source="SREASON">2110</ref>
    </refs>
    <vuln_soft>
      <prod vendor="packeteer" name="packetwise">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0114" published="2007-01-08" name="CVE-2007-0114" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sun Java System Content Delivery Server 5.0 and 5.0 PU1 allows remote attackers to obtain sensitive information regarding "content details" via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102764-1" source="SUNALERT" patch="1">102764</ref>
      <ref url="http://secunia.com/advisories/23630" source="SECUNIA" patch="1" adv="1">23630</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31345" source="XF">sun-java-cds-info-disclosure(31345)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0076" source="VUPEN">ADV-2007-0076</ref>
      <ref url="http://www.securityfocus.com/bid/21908" source="BID">21908</ref>
      <ref url="http://osvdb.org/32645" source="OSVDB">32645</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_content_delivery_server">
        <vers num="5.0" edition=""/>
        <vers num="5.0" edition=":solaris"/>
        <vers num="5.0" edition="pu1"/>
        <vers num="5.0" edition="pu1:solaris"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0115" published="2007-01-08" name="CVE-2007-0115" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Static code injection vulnerability in Coppermine Photo Gallery 1.4.10 and earlier allows remote authenticated administrators to execute arbitrary PHP code via the Username to login.php, which is injected into an error message in security.log.php, which can then be accessed using viewlog.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456051/100/0/threaded" source="BUGTRAQ">20070105 Coppermine Photo Gallery &lt;= 1.4.10 SQL Injection Exploit</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001218.html" source="VIM">20070108 Source verify - Coppermine Photo Gallery &lt;= 1.4.10 code injection</ref>
      <ref url="http://osvdb.org/33383" source="OSVDB">33383</ref>
      <ref url="http://acid-root.new.fr/poc/19070104.txt" source="MISC">http://acid-root.new.fr/poc/19070104.txt</ref>
      <ref url="http://securityreason.com/securityalert/2107" source="SREASON">2107</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coppermine" name="coppermine_photo_gallery">
        <vers prev="1" num="1.4.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0116" published="2007-01-08" name="CVE-2007-0116" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Digger Solutions Intranet Open Source (IOS) stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for data/intranet.mdb.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456047/100/0/threaded" source="BUGTRAQ">20070105 Intranet Open Source Remote Password Disclosure "intranet.mdb"</ref>
      <ref url="http://osvdb.org/33379" source="OSVDB">33379</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31308" source="XF">intranet-intranet-info-disclosure(31308)</ref>
      <ref url="http://securityreason.com/securityalert/2109" source="SREASON">2109</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digger_solutions" name="intranet_open_source">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0117" published="2007-01-08" name="CVE-2007-0117" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly validate Bill of Materials (BOM) files, which allows attackers to gain privileges via a BOM file under /Library/Receipts/, which triggers arbitrary file permission changes upon execution of a diskutil permission repair operation.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0074" source="VUPEN">ADV-2007-0074</ref>
      <ref url="http://www.securityfocus.com/bid/21899" source="BID">21899</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-05-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-05-01-2007.html</ref>
      <ref url="http://osvdb.org/31167" source="OSVDB">31167</ref>
      <ref url="http://secunia.com/advisories/23653" source="SECUNIA">23653</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0118" published="2007-01-08" name="CVE-2007-0118" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an absolute pathname in the file parameter to (1) edittag.cgi, (2) edittag.pl, (3) edittag_mp.cgi, or (4) edittag_mp.pl.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21890" source="BID" adv="1">21890</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456055/100/0/threaded" source="BUGTRAQ">20070105 Multiple bugs in EditTag</ref>
      <ref url="http://osvdb.org/33396" source="OSVDB">33396</ref>
      <ref url="http://osvdb.org/33395" source="OSVDB">33395</ref>
      <ref url="http://osvdb.org/33394" source="OSVDB">33394</ref>
      <ref url="http://osvdb.org/33393" source="OSVDB">33393</ref>
      <ref url="http://secunia.com/advisories/7950" source="SECUNIA">7950</ref>
    </refs>
    <vuln_soft>
      <prod vendor="edittag" name="edittag">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0119" published="2007-01-08" name="CVE-2007-0119" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in EditTag 1.2 allow remote attackers to inject arbitrary web script or HTML via the plain parameter to (1) mkpw_mp.cgi, (2) mkpw.pl, or (3) mkpw.cgi.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21891" source="BID" adv="1">21891</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456055/100/0/threaded" source="BUGTRAQ" adv="1">20070105 Multiple bugs in EditTag</ref>
      <ref url="http://osvdb.org/33392" source="OSVDB">33392</ref>
      <ref url="http://osvdb.org/33391" source="OSVDB">33391</ref>
      <ref url="http://osvdb.org/33390" source="OSVDB">33390</ref>
      <ref url="http://secunia.com/advisories/7950" source="SECUNIA">7950</ref>
    </refs>
    <vuln_soft>
      <prod vendor="edittag" name="edittag">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0120" published="2007-01-08" name="CVE-2007-0120" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">Acunetix Web Vulnerability Scanner (WVS) 4.0 Build 20060717 and earlier allows remote attackers to cause a denial of service (application crash) via multiple HTTP requests containing invalid Content-Length values.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31279" source="XF" patch="1">acunetix-content-length-dos(31279)</ref>
      <ref url="http://www.securityfocus.com/bid/21898" source="BID">21898</ref>
      <ref url="http://osvdb.org/37580" source="OSVDB">37580</ref>
      <ref url="http://milw0rm.com/exploits/3078" source="MILW0RM">3078</ref>
    </refs>
    <vuln_soft>
      <prod vendor="acunetix" name="web_vulnerability_scanner">
        <vers prev="1" num="4.0_build_2006-07-17"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0121" published="2007-01-08" name="CVE-2007-0121" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.asp in RI Blog 1.3 allows remote attackers to inject arbitrary web script or HTML via the q parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0083" source="VUPEN">ADV-2007-0083</ref>
      <ref url="http://www.securityfocus.com/bid/21880" source="BID" adv="1">21880</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456052/100/0/threaded" source="BUGTRAQ">20070105 RI Blog 1.3 XSS Vuln.</ref>
      <ref url="http://osvdb.org/31637" source="OSVDB">31637</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31317" source="XF">riblog-search-xss(31317)</ref>
      <ref url="http://securityreason.com/securityalert/2108" source="SREASON">2108</ref>
      <ref url="http://secunia.com/advisories/23657" source="SECUNIA">23657</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_romedahl" name="ri_blog">
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0122" published="2007-01-08" name="CVE-2007-0122" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and earlier allow remote authenticated administrators to execute arbitrary SQL commands via (1) the cat parameter to albmgr.php, and possibly (2) the gid parameter to usermgr.php; (3) the start parameter to db_ecard.php; and the albumid parameter to unspecified files, related to the (4) filename_to_title and (5) del_titles functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21894" source="BID">21894</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456051/100/0/threaded" source="BUGTRAQ" adv="1">20070105 Coppermine Photo Gallery &lt;= 1.4.10 SQL Injection Exploit</ref>
      <ref url="http://osvdb.org/35856" source="OSVDB">35856</ref>
      <ref url="http://osvdb.org/35855" source="OSVDB">35855</ref>
      <ref url="http://osvdb.org/35854" source="OSVDB">35854</ref>
      <ref url="http://osvdb.org/35853" source="OSVDB">35853</ref>
      <ref url="http://osvdb.org/35852" source="OSVDB">35852</ref>
      <ref url="http://acid-root.new.fr/poc/19070104.txt" source="MISC">http://acid-root.new.fr/poc/19070104.txt</ref>
      <ref url="http://securityreason.com/securityalert/2123" source="SREASON">2123</ref>
      <ref url="http://secunia.com/advisories/25846" source="SECUNIA">25846</ref>
      <ref url="http://milw0rm.com/exploits/3085" source="MILW0RM">3085</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coppermine" name="coppermine_photo_gallery">
        <vers num="1.0"/>
        <vers num="1.0_rc3"/>
        <vers num="1.1"/>
        <vers num="1.1_beta_2"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2_b"/>
        <vers num="1.2.2_b-nuke"/>
        <vers num="1.3"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers prev="1" num="1.4.10"/>
        <vers num="1.4.4"/>
        <vers num="1.4.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0123" published="2007-01-08" name="CVE-2007-0123" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in Uber Uploader 4.2 allows remote attackers to upload and execute arbitrary PHP scripts by naming them with a .phtml extension, which bypasses the .php extension check but is still executable on some server configurations.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456045/100/0/threaded" source="BUGTRAQ" adv="1">20070105 Uber Uploader 4.2 Arbitrary File Upload Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31303" source="XF">uber-uploader-phtml-file-upload(31303)</ref>
      <ref url="http://securityreason.com/securityalert/2116" source="SREASON">2116</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uber_uploader" name="uber_uploader">
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0124" published="2007-01-08" name="CVE-2007-0124" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:P)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Drupal before 4.6.11, and 4.7 before 4.7.5, when MySQL is used, allows remote authenticated users to cause a denial of service by poisoning the page cache via unspecified vectors, which triggers erroneous 404 HTTP errors for pages that exist.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21895" source="BID" patch="1" adv="1">21895</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456056/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20070105 [DRUPAL-SA-2007-002] Drupal 4.6.11 / 4.7.5 fixes DoS issue</ref>
      <ref url="http://secunia.com/advisories/23586" source="SECUNIA" patch="1" adv="1">23586</ref>
      <ref url="http://drupal.org/node/104238" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/104238</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0051" source="VUPEN">ADV-2007-0051</ref>
      <ref url="http://osvdb.org/32131" source="OSVDB">32131</ref>
      <ref url="http://securityreason.com/securityalert/2115" source="SREASON">2115</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="drupal">
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.6.1"/>
        <vers num="4.6.10"/>
        <vers num="4.6.2"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="4.6.5"/>
        <vers num="4.6.6"/>
        <vers num="4.6.7"/>
        <vers num="4.6.8"/>
        <vers num="4.6.9"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.7.3"/>
        <vers num="4.7.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0125" published="2007-01-08" name="CVE-2007-0125" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Kaspersky Labs Antivirus Engine 6.0 for Windows and 5.5-10 for Linux before 20070102 enter an infinite loop upon encountering an invalid NumberOfRvaAndSizes value in the Optional Windows Header of a portable executable (PE) file, which allows remote attackers to cause a denial of service (CPU consumption) by scanning a crafted PE file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31315" source="XF">kaspersky-antivirus-pe-dos(31315)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0067" source="VUPEN">ADV-2007-0067</ref>
      <ref url="http://www.securityfocus.com/bid/21901" source="BID">21901</ref>
      <ref url="http://securitytracker.com/id?1017476" source="SECTRACK">1017476</ref>
      <ref url="http://secunia.com/advisories/23575" source="SECUNIA" adv="1">23575</ref>
      <ref url="http://osvdb.org/32588" source="OSVDB">32588</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=459" source="IDEFENSE" adv="1">20070105 Kaspersky Antivirus Scan Engine PE File Denial of Service Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kaspersky_lab" name="kaspersky_antivirus_engine">
        <vers num="5.5.10" edition=""/>
        <vers num="5.5.10" edition=":linux"/>
        <vers num="6.0" edition=""/>
        <vers num="6.0" edition=":windows"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0126" published="2007-01-08" name="CVE-2007-0126" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Opera 9.02 allows remote attackers to execute arbitrary code via a JPEG file with an invalid number of index bytes in the Define Huffman Table (DHT) marker.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.opera.com/support/search/supsearch.dml?index=852" source="CONFIRM" patch="1" adv="1">http://www.opera.com/support/search/supsearch.dml?index=852</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31305" source="XF">opera-jpeg-dht-bo(31305)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0060" source="VUPEN">ADV-2007-0060</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200701-08.xml" source="GENTOO">GLSA-200701-08</ref>
      <ref url="http://securitytracker.com/id?1017473" source="SECTRACK">1017473</ref>
      <ref url="http://secunia.com/advisories/23771" source="SECUNIA">23771</ref>
      <ref url="http://secunia.com/advisories/23739" source="SECUNIA">23739</ref>
      <ref url="http://secunia.com/advisories/23613" source="SECUNIA" adv="1">23613</ref>
      <ref url="http://osvdb.org/31574" source="OSVDB">31574</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0009.html" source="SUSE">SUSE-SA:2007:009</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=457" source="IDEFENSE" adv="1">20070105 Opera Software Opera Web Browser JPG Image DHT Marker Heap Corruption Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera" name="opera_browser">
        <vers num="9.02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0127" published="2007-01-08" name="CVE-2007-0127" modified="2011-03-07" discovered="2006-11-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Javascript SVG support in Opera before 9.10 does not properly validate object types in a createSVGTransformFromMatrix request, which allows remote attackers to execute arbitrary code via JavaScript code that uses an invalid object in this request that causes a controlled pointer to be referenced during the virtual function call.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
      <design/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23613" source="SECUNIA" patch="1" adv="1">23613</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=458" source="IDEFENSE" patch="1" adv="1">20070105 Opera Software Opera Web Browser createSVGTransformFromMatrix Object Typecasting Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0060" source="VUPEN">ADV-2007-0060</ref>
      <ref url="http://www.opera.com/support/search/supsearch.dml?index=851" source="CONFIRM">http://www.opera.com/support/search/supsearch.dml?index=851</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200701-08.xml" source="GENTOO">GLSA-200701-08</ref>
      <ref url="http://securitytracker.com/id?1017473" source="SECTRACK">1017473</ref>
      <ref url="http://secunia.com/advisories/23771" source="SECUNIA" adv="1">23771</ref>
      <ref url="http://secunia.com/advisories/23739" source="SECUNIA" adv="1">23739</ref>
      <ref url="http://osvdb.org/31575" source="OSVDB">31575</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0009.html" source="SUSE">SUSE-SA:2007:009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera" name="opera_browser">
        <vers num="1.00"/>
        <vers num="2.00"/>
        <vers num="2.10" edition="beta1"/>
        <vers num="2.10" edition="beta2"/>
        <vers num="2.10" edition="beta3"/>
        <vers num="2.12"/>
        <vers num="3.00" edition="beta"/>
        <vers num="3.10"/>
        <vers num="3.21"/>
        <vers num="3.50"/>
        <vers num="3.51"/>
        <vers num="3.60"/>
        <vers num="3.61"/>
        <vers num="3.62" edition="beta"/>
        <vers num="4.00" edition="beta2"/>
        <vers num="4.00" edition="beta3"/>
        <vers num="4.00" edition="beta4"/>
        <vers num="4.00" edition="beta5"/>
        <vers num="4.00" edition="beta6"/>
        <vers num="4.01"/>
        <vers num="4.02"/>
        <vers num="5.0" edition="beta2"/>
        <vers num="5.0" edition="beta3"/>
        <vers num="5.0" edition="beta4"/>
        <vers num="5.0" edition="beta5"/>
        <vers num="5.0" edition="beta6"/>
        <vers num="5.0" edition="beta7"/>
        <vers num="5.0" edition="beta8"/>
        <vers num="5.02"/>
        <vers num="5.10"/>
        <vers num="5.11"/>
        <vers num="5.12"/>
        <vers num="6.0" edition="beta1"/>
        <vers num="6.0" edition="beta2"/>
        <vers num="6.0" edition="tp1"/>
        <vers num="6.0" edition="tp2"/>
        <vers num="6.0" edition="tp3"/>
        <vers num="6.01"/>
        <vers num="6.02"/>
        <vers num="6.03"/>
        <vers num="6.04"/>
        <vers num="6.05"/>
        <vers num="6.06"/>
        <vers num="6.1" edition="beta1"/>
        <vers num="6.11"/>
        <vers num="6.12"/>
        <vers num="7.0" edition="beta1"/>
        <vers num="7.0" edition="beta1_v2"/>
        <vers num="7.0" edition="beta2"/>
        <vers num="7.01"/>
        <vers num="7.02"/>
        <vers num="7.03"/>
        <vers num="7.10" edition="beta1"/>
        <vers num="7.11" edition="beta2"/>
        <vers num="7.20" edition="beta7"/>
        <vers num="7.21"/>
        <vers num="7.22"/>
        <vers num="7.23"/>
        <vers num="7.50" edition="beta1"/>
        <vers num="7.51"/>
        <vers num="7.52"/>
        <vers num="7.53"/>
        <vers num="7.54" edition="update1"/>
        <vers num="7.54" edition="update2"/>
        <vers num="7.60"/>
        <vers num="8.0" edition="beta1"/>
        <vers num="8.0" edition="beta2"/>
        <vers num="8.0" edition="beta3"/>
        <vers num="8.01"/>
        <vers num="8.02"/>
        <vers num="8.50"/>
        <vers num="8.51"/>
        <vers num="8.52"/>
        <vers num="8.53"/>
        <vers num="8.54"/>
        <vers num="9.0" edition="beta1"/>
        <vers num="9.0" edition="beta2"/>
        <vers num="9.01"/>
        <vers prev="1" num="9.02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0128" published="2007-01-09" name="CVE-2007-0128" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in info_book.asp in Digirez 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the book_id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0053" source="VUPEN">ADV-2007-0053</ref>
      <ref url="http://secunia.com/advisories/23606" source="SECUNIA" adv="1">23606</ref>
      <ref url="http://osvdb.org/31677" source="OSVDB">31677</ref>
      <ref url="http://milw0rm.com/exploits/3081" source="MILW0RM">3081</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digiappz" name="digirez">
        <vers prev="1" num="3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0129" published="2007-01-09" name="CVE-2007-0129" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in main.asp in LocazoList 2.01a beta5 and earlier allows remote attackers to execute arbitrary SQL commands via the subcatID parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31242" source="XF">locazolist-main-sql-injection(31242)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0052" source="VUPEN">ADV-2007-0052</ref>
      <ref url="http://osvdb.org/35813" source="OSVDB">35813</ref>
      <ref url="http://milw0rm.com/exploits/3073" source="MILW0RM">3073</ref>
    </refs>
    <vuln_soft>
      <prod vendor="locazo" name="locazolist_classifieds">
        <vers prev="1" num="2.01a_beta5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0130" published="2007-01-09" name="CVE-2007-0130" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in user.php in iGeneric iG Calendar 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0055" source="VUPEN">ADV-2007-0055</ref>
      <ref url="http://www.securityfocus.com/bid/21873" source="BID">21873</ref>
      <ref url="http://secunia.com/advisories/23602" source="SECUNIA" adv="1">23602</ref>
      <ref url="http://osvdb.org/31678" source="OSVDB">31678</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31300" source="XF">igcalendar-user-sql-injection(31300)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456044/100/0/threaded" source="BUGTRAQ">20070105 IG Calendar SQL Injection</ref>
      <ref url="http://milw0rm.com/exploits/3082" source="MILW0RM">3082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="igeneric" name="ig_calendar">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0131" published="2007-01-09" name="CVE-2007-0131" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">JAMWiki before 0.5.0 does not properly check permissions during moves of "read-only or admin-only topics," which allows remote attackers to make unauthorized changes to the wiki.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=171441&amp;release_id=475663" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=171441&amp;release_id=475663</ref>
      <ref url="http://secunia.com/advisories/23634" source="SECUNIA">23634</ref>
      <ref url="http://osvdb.org/32581" source="OSVDB">32581</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31296" source="XF">jamwiki-permission-security-bypass(31296)</ref>
      <ref url="http://www.securityfocus.com/bid/21879" source="BID">21879</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jamwiki" name="jamwiki">
        <vers prev="1" num="0.4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0132" published="2007-01-09" name="CVE-2007-0132" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in compare_product.php in iGeneric iG Shop 1.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0056" source="VUPEN">ADV-2007-0056</ref>
      <ref url="http://secunia.com/advisories/23604" source="SECUNIA" adv="1">23604</ref>
      <ref url="http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt" source="MISC">http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt</ref>
      <ref url="http://osvdb.org/33385" source="OSVDB">33385</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31299" source="XF">igshop-compareproduct-sql-injection(31299)</ref>
      <ref url="http://www.securityfocus.com/bid/21874" source="BID">21874</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456043/100/0/threaded" source="BUGTRAQ">20070105 IG Shop remote code execution</ref>
      <ref url="http://milw0rm.com/exploits/3083" source="MILW0RM">3083</ref>
    </refs>
    <vuln_soft>
      <prod vendor="igeneric" name="ig_shop">
        <vers num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0133" published="2007-01-09" name="CVE-2007-0133" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in display_review.php in iGeneric iG Shop 1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) user_login_cookie parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0056" source="VUPEN">ADV-2007-0056</ref>
      <ref url="http://osvdb.org/33386" source="OSVDB">33386</ref>
    </refs>
    <vuln_soft>
      <prod vendor="igeneric" name="ig_shop">
        <vers prev="1" num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0134" published="2007-01-09" name="CVE-2007-0134" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple eval injection vulnerabilities in iGeneric iG Shop 1.0 allow remote attackers to execute arbitrary code via the action parameter, which is supplied to an eval function call in (1) cart.php and (2) page.php.  NOTE: a later report and CVE analysis indicate that the vulnerability is present in 1.4.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31301" source="XF">igshop-cartpage-code-execution(31301)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0056" source="VUPEN" adv="1">ADV-2007-0056</ref>
      <ref url="http://www.securityfocus.com/bid/21875" source="BID">21875</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/471722/100/0/threaded" source="BUGTRAQ">20070619 iG Shop 1.4 eval Inclusion Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456043/100/0/threaded" source="BUGTRAQ">20070105 IG Shop remote code execution</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-June/001664.html" source="VIM">20070618 Dup: iG Shop 1.4 (page.php) Remote Code Execution Exploit</ref>
      <ref url="http://secunia.com/advisories/23604" source="SECUNIA" adv="1">23604</ref>
      <ref url="http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt" source="MISC">http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt</ref>
      <ref url="http://osvdb.org/33388" source="OSVDB">33388</ref>
      <ref url="http://osvdb.org/33387" source="OSVDB">33387</ref>
      <ref url="http://milw0rm.com/exploits/3083" source="MILW0RM">3083</ref>
    </refs>
    <vuln_soft>
      <prod vendor="igeneric" name="ig_shop">
        <vers num="1.0"/>
        <vers num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0135" published="2007-01-09" name="CVE-2007-0135" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in inc/init.inc.php in Aratix 0.2.2 beta 11 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the current_path parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0054" source="VUPEN">ADV-2007-0054</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001219.html" source="VIM">20070108 Source verify of Aratix RFI</ref>
      <ref url="http://securityreason.com/exploitalert/1698" source="MISC">http://securityreason.com/exploitalert/1698</ref>
      <ref url="http://osvdb.org/33405" source="OSVDB">33405</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31282" source="XF">aratix-init-file-include(31282)</ref>
      <ref url="http://milw0rm.com/exploits/3079" source="MILW0RM">3079</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aratix" name="aratix">
        <vers prev="1" num="0.2.2_beta_11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0136" published="2007-01-09" name="CVE-2007-0136" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Drupal before 4.6.11, and 4.7 before 4.7.5, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in the (1) filter and (2) system modules.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://drupal.org/node/104233" source="CONFIRM" patch="1">http://drupal.org/node/104233</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0050" source="VUPEN">ADV-2007-0050</ref>
      <ref url="http://osvdb.org/32140" source="OSVDB">32140</ref>
      <ref url="http://osvdb.org/32139" source="OSVDB">32139</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=116799778408115&amp;w=2" source="FULLDISC">20070105 [DRUPAL-SA-2007-001] Drupal 4.6.11 / 4.7.5 fixes</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31311" source="XF">drupal-core-unspecified-xss(31311)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456054/100/100/threaded" source="BUGTRAQ">20070105 [DRUPAL-SA-2007-001] Drupal 4.6.11 / 4.7.5 fixes XSS issue</ref>
      <ref url="http://drupal.org/files/sa-2007-001/advisory.txt" source="CONFIRM">http://drupal.org/files/sa-2007-001/advisory.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="drupal">
        <vers prev="1" num="4.6.10"/>
        <vers prev="1" num="4.7.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0137" published="2007-01-09" name="CVE-2007-0137" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in SimpleBoxes/SerendipityNZ Serene Bach 2.05R and earlier, and 2.08D and earlier in the 2.08 series; and (2) sb 1.13D and earlier, and 1.18R and earlier in the 1.18 series; allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23623" source="SECUNIA" patch="1" adv="1">23623</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0065" source="VUPEN">ADV-2007-0065</ref>
      <ref url="http://serenebach.net/log/sb209R.html" source="CONFIRM">http://serenebach.net/log/sb209R.html</ref>
      <ref url="http://serenebach.net/log/sb119R.html" source="CONFIRM">http://serenebach.net/log/sb119R.html</ref>
      <ref url="http://osvdb.org/32580" source="OSVDB">32580</ref>
      <ref url="http://jvn.jp/jp/JVN%2365500885/index.html" source="JVN">JVN#65500885</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31302" source="XF">serene-bach-unspecified-xss(31302)</ref>
      <ref url="http://www.securityfocus.com/bid/21884" source="BID">21884</ref>
      <ref url="http://securitytracker.com/id?1017470" source="SECTRACK">1017470</ref>
    </refs>
    <vuln_soft>
      <prod vendor="serendipitynz" name="serene_bach">
        <vers num="1.18r"/>
        <vers num="2.05r"/>
        <vers num="2.08d"/>
      </prod>
      <prod vendor="serendipitynz" name="serene_bach_sb">
        <vers num="1.13d"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0138" published="2007-01-09" name="CVE-2007-0138" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with (1) AbfrageForm or (2) EingabeForm, allows remote attackers to cause a denial of service (daemon crash) via multiple requests containing many /../ sequences in the Name parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31216" source="XF">formbankserver-formbank-dos(31216)</ref>
      <ref url="http://secunia.com/advisories/23539" source="SECUNIA" adv="1">23539</ref>
      <ref url="http://osvdb.org/32546" source="OSVDB">32546</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fersch" name="formbankserver">
        <vers num="1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0139" published="2007-01-09" name="CVE-2007-0139" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the DECnet-Plus 7.3-2 feature in DECnet/OSI 7.3-2 for OpenVMS ALPHA, and the DECnet-Plus 7.3 feature in DECnet/OSI 7.3 for OpenVMS VAX, allows attackers to obtain "unintended privileged access to data and system resources" via unspecified vectors, related to (1) [SYSEXE]CTF$UI.EXE, (2) [SYSMSG]CTF$MESSAGES.EXE, (3) [SYSHLP]CTF$HELP.HLB, and (4) [SYSMGR]CTF$STARTUP.COM.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23636" source="SECUNIA" patch="1" adv="1">23636</ref>
      <ref url="ftp://ftp.itrc.hp.com/openvms_patches/vax/V7.3/VAX_DNVOSIMUP01-V0703.txt" source="CONFIRM" patch="1">ftp://ftp.itrc.hp.com/openvms_patches/vax/V7.3/VAX_DNVOSIMUP01-V0703.txt</ref>
      <ref url="ftp://ftp.itrc.hp.com/openvms_patches/alpha/V7.3-2/AXP_DNVOSIMUP01-V0703-2.txt" source="CONFIRM" patch="1">ftp://ftp.itrc.hp.com/openvms_patches/alpha/V7.3-2/AXP_DNVOSIMUP01-V0703-2.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0063" source="VUPEN">ADV-2007-0063</ref>
      <ref url="http://osvdb.org/32586" source="OSVDB">32586</ref>
      <ref url="http://osvdb.org/32585" source="OSVDB">32585</ref>
      <ref url="http://osvdb.org/32584" source="OSVDB">32584</ref>
      <ref url="http://osvdb.org/32583" source="OSVDB">32583</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openvms">
        <vers num="7.3" edition=""/>
        <vers num="7.3" edition=":openvms_vax"/>
        <vers num="7.3_2" edition=""/>
        <vers num="7.3_2" edition=":openvms_vax"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0140" published="2007-01-09" name="CVE-2007-0140" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in down.asp in Kolayindir Download (Yenionline) allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0079" source="VUPEN">ADV-2007-0079</ref>
      <ref url="http://www.securityfocus.com/bid/21889" source="BID">21889</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456068/100/0/threaded" source="BUGTRAQ">20070105 Kolayindir Download (Yenionline) (tr) SqL Injection Vuln.</ref>
      <ref url="http://secunia.com/advisories/23645" source="SECUNIA" adv="1">23645</ref>
      <ref url="http://osvdb.org/31625" source="OSVDB">31625</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31320" source="XF">kolayindirdownload-down-sql-injection(31320)</ref>
      <ref url="http://securityreason.com/securityalert/2122" source="SREASON">2122</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kolayindir_download" name="kolayindir_download">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0141" published="2007-01-09" name="CVE-2007-0141" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in yald.php in Yet Another Link Directory 1.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0082" source="VUPEN">ADV-2007-0082</ref>
      <ref url="http://www.securityfocus.com/bid/21904" source="BID">21904</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456122/100/0/threaded" source="BUGTRAQ">20070106 Yet Another Link Directory v1.0</ref>
      <ref url="http://secunia.com/advisories/23646" source="SECUNIA" adv="1">23646</ref>
      <ref url="http://osvdb.org/31626" source="OSVDB">31626</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31322" source="XF">yald-yald-xss(31322)</ref>
      <ref url="http://securityreason.com/securityalert/2121" source="SREASON">2121</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yet_another_link_directory" name="yet_another_link_directory">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0142" published="2007-01-09" name="CVE-2007-0142" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in orange.asp in ShopStoreNow E-commerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the CatID parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0080" source="VUPEN">ADV-2007-0080</ref>
      <ref url="http://www.securityfocus.com/bid/21905" source="BID">21905</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456127/100/0/threaded" source="BUGTRAQ">20070106 shopstorenow (orange.asp) sql injection</ref>
      <ref url="http://secunia.com/advisories/23642" source="SECUNIA" adv="1">23642</ref>
      <ref url="http://osvdb.org/31665" source="OSVDB">31665</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31313" source="XF">shopstorenow-orange-sql-injection(31313)</ref>
      <ref url="http://securityreason.com/securityalert/2120" source="SREASON">2120</ref>
    </refs>
    <vuln_soft>
      <prod vendor="shopstorenow" name="e-commerce_shopping_cart">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0143" published="2007-01-09" name="CVE-2007-0143" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in NUNE News Script 2.0pre2 allow remote attackers to execute arbitrary PHP code via a URL in the custom_admin_path parameter to (1) index.php or (2) archives.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0078" source="VUPEN">ADV-2007-0078</ref>
      <ref url="http://secunia.com/advisories/23635" source="SECUNIA" adv="1">23635</ref>
      <ref url="http://osvdb.org/31209" source="OSVDB">31209</ref>
      <ref url="http://osvdb.org/31208" source="OSVDB">31208</ref>
      <ref url="http://milw0rm.com/exploits/3090" source="MILW0RM">3090</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31312" source="XF">nune-index-archives-file-include(31312)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456242/100/0/threaded" source="BUGTRAQ">20070107 NUNE News Script (custom_admin_path) Remote File Include Vulnerablity</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nune" name="news_script">
        <vers num="2.0_pre2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0144" published="2007-01-09" name="CVE-2007-0144" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the ordernum parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23652" source="SECUNIA" adv="1">23652</ref>
      <ref url="http://osvdb.org/31690" source="OSVDB">31690</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31321" source="XF">qos-search-xss(31321)</ref>
      <ref url="http://milw0rm.com/exploits/3089" source="MILW0RM">3089</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digitizing_quote_and_ordering_system" name="digitizing_quote_and_ordering_system">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0145" published="2007-01-09" name="CVE-2007-0145" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in bn_smrep1.php in BinGoPHP News (BP News) 3.01 allows remote attackers to execute arbitrary PHP code via a URL in the bnrep parameter, a different vector than CVE-2006-4648 and CVE-2006-4649.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1017477" source="SECTRACK">1017477</ref>
      <ref url="http://osvdb.org/35898" source="OSVDB">35898</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31328" source="XF">bingo-bnsmrep1-file-include(31328)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bingo_news" name="bingo_news">
        <vers num="3.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0146" published="2007-01-09" name="CVE-2007-0146" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Fix and Chips CMS 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in (a) delete-announce.php; the (2) Announcement form field in (b) staff.php; the (3) Client Name, (4) Business Name, (5) Street, (6) Address 2, (7) Town/City, (8) Postcode, (9) Phone Number, (10) Email Address and (11) Website Address form fields in (c) new_customer.php; and unspecified fields in (d) search.php and (e) client-results.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0081" source="VUPEN">ADV-2007-0081</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456121/100/0/threaded" source="BUGTRAQ">20070106 Fix &amp; Chips CMS v1.0</ref>
      <ref url="http://secunia.com/advisories/23625" source="SECUNIA" adv="1">23625</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31319" source="XF">fixandchips-multiple-scripts-xss(31319)</ref>
      <ref url="http://www.osvdb.org/32650" source="OSVDB">32650</ref>
      <ref url="http://www.osvdb.org/32649" source="OSVDB">32649</ref>
      <ref url="http://www.osvdb.org/32648" source="OSVDB">32648</ref>
      <ref url="http://www.osvdb.org/32647" source="OSVDB">32647</ref>
      <ref url="http://www.osvdb.org/32646" source="OSVDB">32646</ref>
      <ref url="http://securityreason.com/securityalert/2119" source="SREASON">2119</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fix_and_chips_computer_services" name="fix_and_chips_cms">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0147" published="2007-01-09" name="CVE-2007-0147" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cuyahoga before 1.0.1 installs the FCKEditor component with an incorrect deny statement in a Web.config file, which allows remote attackers to upload files when these privileges were intended only for the Administrator and Editor roles.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.cuyahoga-project.org/10/section.aspx/61" source="CONFIRM" patch="1">http://www.cuyahoga-project.org/10/section.aspx/61</ref>
      <ref url="http://secunia.com/advisories/23662" source="SECUNIA" patch="1" adv="1">23662</ref>
      <ref url="http://cuyahoga.svn.sourceforge.net/viewvc/cuyahoga?view=rev&amp;revision=551" source="CONFIRM" patch="1">http://cuyahoga.svn.sourceforge.net/viewvc/cuyahoga?view=rev&amp;revision=551</ref>
      <ref url="http://osvdb.org/32643" source="OSVDB">32643</ref>
      <ref url="http://www.securityfocus.com/bid/21927" source="BID">21927</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cuyahoga" name="cuyahoga">
        <vers prev="1" num="1.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0148" published="2007-01-09" name="CVE-2007-0148" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Format string vulnerability in OmniGroup OmniWeb 5.5.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in the Javascript alert function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.omnigroup.com/applications/omniweb/releasenotes/" source="CONFIRM" patch="1">http://www.omnigroup.com/applications/omniweb/releasenotes/</ref>
      <ref url="http://secunia.com/advisories/23624" source="SECUNIA" patch="1" adv="1">23624</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0075" source="VUPEN">ADV-2007-0075</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-07-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-07-01-2007.html</ref>
      <ref url="http://osvdb.org/31222" source="OSVDB">31222</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31324" source="XF">omniweb-alert-format-string(31324)</ref>
      <ref url="http://www.securityfocus.com/bid/21911" source="BID">21911</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456578/100/0/threaded" source="BUGTRAQ">20070111 DMA[2007-0107a] OmniWeb Javascript Alert Format String Vulnerabiity and DMA[2007-0109a] Apple Finder Disk Image Volume Label Overflow / DoS</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2007-0107a%5D.txt" source="MISC">http://www.digitalmunition.com/DMA%5B2007-0107a%5D.txt</ref>
      <ref url="http://milw0rm.com/exploits/3098" source="MILW0RM">3098</ref>
      <ref url="http://blog.omnigroup.com/2007/01/07/omniweb-552-now-available-and-more-secure/" source="CONFIRM">http://blog.omnigroup.com/2007/01/07/omniweb-552-now-available-and-more-secure/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="omnigroup" name="omniweb">
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0149" published="2007-01-09" name="CVE-2007-0149" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">EMembersPro 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for users.mdb.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456228/100/0/threaded" source="BUGTRAQ">20070107 EMembersPro 1.0 Remote Password Disclosure Vulnerability</ref>
      <ref url="http://osvdb.org/33403" source="OSVDB">33403</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31329" source="XF">ememberspro-users-info-disclosure(31329)</ref>
      <ref url="http://securityreason.com/securityalert/2118" source="SREASON">2118</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ememberspro" name="ememberspro">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0150" published="2007-01-09" name="CVE-2007-0150" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in index.php in Dayfox Blog allow remote attackers to execute arbitrary PHP code via a URL in the (1) page, (2) subject, and (3) q parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0099" source="VUPEN">ADV-2007-0099</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456212/100/0/threaded" source="BUGTRAQ">20070107 Dayfox Blog Remote File Include Vuln.</ref>
      <ref url="http://osvdb.org/31259" source="OSVDB">31259</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31336" source="XF">dayfoxblog-index-file-include(31336)</ref>
      <ref url="http://securityreason.com/securityalert/2117" source="SREASON">2117</ref>
      <ref url="http://secunia.com/advisories/23661" source="SECUNIA">23661</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dayfox_designs" name="dayfox_blog">
        <vers num="4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0151" published="2007-01-09" name="CVE-2007-0151" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">MitiSoft stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for access_MS/MitiSoft.mdb.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456230/100/0/threaded" source="BUGTRAQ">20070107 MitiSoft Remote Password Disclosure Vulnerability</ref>
      <ref url="http://osvdb.org/33409" source="OSVDB">33409</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31341" source="XF">mitisoft-mitisoft-info-disclosure(31341)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mitisoft" name="mitisoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0152" published="2007-01-09" name="CVE-2007-0152" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">OhhASP stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/OhhASP.mdb.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456117/100/0/threaded" source="BUGTRAQ">20070106 ohhASP Remote Password Disclosure</ref>
      <ref url="http://osvdb.org/33381" source="OSVDB">33381</ref>
      <ref url="http://64.38.62.221/ariasecucom/forum/showthread.php?t=89" source="MISC">http://64.38.62.221/ariasecucom/forum/showthread.php?t=89</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31342" source="XF">ohhasp-ohhasp-info-disclosure(31342)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ohhasp" name="ohhasp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0153" published="2007-01-09" name="CVE-2007-0153" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">AJLogin 3.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for ajlogin.mdb.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456226/100/0/threaded" source="BUGTRAQ">20070107 AJLogin v3.5 Remote Password Disclosure Vulnerability</ref>
      <ref url="http://osvdb.org/33404" source="OSVDB">33404</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31331" source="XF">ajlogin-ajlogin-info-disclosure(31331)</ref>
      <ref url="http://securityreason.com/securityalert/2127" source="SREASON">2127</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adam_jarret" name="ajlogin">
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0154" published="2007-01-09" name="CVE-2007-0154" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Webulas stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/db.mdb.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456239/100/0/threaded" source="BUGTRAQ">20070107 Webulas Remote Password Disclosure Vulnerability</ref>
      <ref url="http://osvdb.org/33401" source="OSVDB">33401</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31338" source="XF">webulas-db-info-disclosure(31338)</ref>
      <ref url="http://securityreason.com/securityalert/2126" source="SREASON">2126</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webulas" name="webulas">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0155" published="2007-01-09" name="CVE-2007-0155" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">HarikaOnline 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for harikaonline.mdb.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456238/100/0/threaded" source="BUGTRAQ">20070107 HarikaOnline v2.0 Remote Password Disclosure Vulnerability</ref>
      <ref url="http://osvdb.org/33410" source="OSVDB">33410</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31339" source="XF">harikaonline-harikaonline-info-disclosure(31339)</ref>
      <ref url="http://securityreason.com/securityalert/2125" source="SREASON">2125</ref>
    </refs>
    <vuln_soft>
      <prod vendor="harikaonline" name="harikaonline">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0156" published="2007-01-09" name="CVE-2007-0156" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">M-Core stores the database under the web document root, which allows remote attackers to obtain sensitive information via a direct request to db/uyelik.mdb.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456235/100/0/threaded" source="BUGTRAQ">20070107 M-Core Remote Password Disclosure Vulnerability</ref>
      <ref url="http://osvdb.org/33402" source="OSVDB">33402</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31340" source="XF">mcore-uyelik-info-disclosure(31340)</ref>
      <ref url="http://securityreason.com/securityalert/2124" source="SREASON">2124</ref>
    </refs>
    <vuln_soft>
      <prod vendor="m-core" name="m-core">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0157" published="2007-01-09" name="CVE-2007-0157" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Array index error in the uri_lookup function in the URI parser for neon 0.26.0 to 0.26.2, possibly only on 64-bit platforms, allows remote malicious servers to cause a denial of service (crash) via a URI with non-ASCII characters, which triggers a buffer under-read due to a type conversion error that generates a negative index.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0362" source="VUPEN">ADV-2007-0362</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0172" source="VUPEN">ADV-2007-0172</ref>
      <ref url="http://osvdb.org/39247" source="OSVDB">39247</ref>
      <ref url="http://mailman.webdav.org/pipermail/neon/2007-January/002362.html" source="MLIST">[neon] 20070107 invalid chars cause sigserv in neon</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=404723" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=404723</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723;msg=5;att=2" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723;msg=5;att=2</ref>
      <ref url="http://www.webdav.org/cadaver/" source="CONFIRM">http://www.webdav.org/cadaver/</ref>
      <ref url="http://www.securityfocus.com/bid/22035" source="BID">22035</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_02_sr.html" source="SUSE">SUSE-SR:2007:002</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:013" source="MANDRIVA">MDKSA-2007:013</ref>
      <ref url="http://secunia.com/advisories/23984" source="SECUNIA">23984</ref>
      <ref url="http://secunia.com/advisories/23763" source="SECUNIA">23763</ref>
      <ref url="http://secunia.com/advisories/23751" source="SECUNIA">23751</ref>
      <ref url="http://mailman.webdav.org/pipermail/cadaver/2007-January/001015.html" source="MLIST">[cadaver] 20070123 release 0.22.5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="neon" name="neon">
        <vers num="0.26.0"/>
        <vers num="0.26.1"/>
        <vers num="0.26.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0159" published="2007-01-09" name="CVE-2007-0159" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the GeoIP_update_database_general function in libGeoIP/GeoIPUpdate.c in GeoIP 1.4.0 allows remote malicious update servers (possibly only update.maxmind.com) to overwrite arbitrary files via a .. (dot dot) in the database filename, which is returned by a request to app/update_getfilename.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://arctic.org/~dean/patches/GeoIP-1.4.0-update-vulnerability.patch" source="MISC" patch="1">http://arctic.org/~dean/patches/GeoIP-1.4.0-update-vulnerability.patch</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0118" source="VUPEN">ADV-2007-0118</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0117" source="VUPEN">ADV-2007-0117</ref>
      <ref url="http://osvdb.org/31618" source="OSVDB">31618</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31383" source="XF">geoip-geoipupdate-directory-traversal(31383)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-412-1" source="UBUNTU">USN-412-1</ref>
      <ref url="http://www.securityfocus.com/bid/21959" source="BID">21959</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:004" source="MANDRIVA">MDKSA-2007:004</ref>
      <ref url="http://secunia.com/advisories/23906" source="SECUNIA">23906</ref>
      <ref url="http://secunia.com/advisories/23880" source="SECUNIA">23880</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geoip" name="geoip">
        <vers num="1.4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0160" published="2007-01-09" name="CVE-2007-0160" modified="2011-08-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the LiveJournal support (hooks/ljhook.cc) in CenterICQ 4.9.11 through 4.21.0, when using unofficial LiveJournal servers, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by adding the victim as a friend and using long (1) username and (2) real name strings.</descript>
    </desc>
    <sols>
      <sol source="nvd">Failed exploitation attempts will likely result in a denial-of-service condition.</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31330" source="XF">centericq-username-bo(31330)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0306" source="VUPEN" adv="1">ADV-2007-0306</ref>
      <ref url="http://www.securityfocus.com/bid/21932" source="BID">21932</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456255/100/0/threaded" source="BUGTRAQ" adv="1">20070107 TK53 Advisory #1: CenterICQ remote DoS buffer overflow in LiveJournal handling</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200701-20.xml" source="GENTOO">GLSA-200701-20</ref>
      <ref url="http://securitytracker.com/id?1017545" source="SECTRACK">1017545</ref>
      <ref url="http://securityreason.com/securityalert/2129" source="SREASON">2129</ref>
      <ref url="http://osvdb.org/33408" source="OSVDB">33408</ref>
    </refs>
    <vuln_soft>
      <prod vendor="centericq" name="centericq">
        <vers num="4.12"/>
        <vers num="4.13"/>
        <vers num="4.14"/>
        <vers num="4.20"/>
        <vers num="4.21"/>
        <vers num="4.9.11"/>
        <vers num="4.9.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0161" published="2007-01-09" name="CVE-2007-0161" modified="2011-03-07" discovered="2006-05-29" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="4.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="2.7" CVSS_base_score="4.1">
    <desc>
      <descript source="cve">The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0094" source="VUPEN">ADV-2007-0094</ref>
      <ref url="http://www.securityfocus.com/bid/21935" source="BID">21935</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456259/100/0/threaded" source="BUGTRAQ" adv="1">20070108 HP Multiple Products PML Driver Local Privilege Escalation</ref>
      <ref url="http://secway.org/advisory/AD20070108.txt" source="MISC" adv="1">http://secway.org/advisory/AD20070108.txt</ref>
      <ref url="http://secunia.com/advisories/23663" source="SECUNIA" adv="1">23663</ref>
      <ref url="http://osvdb.org/32654" source="OSVDB">32654</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31361" source="XF">pml-driver-config-privilege-escalation(31361)</ref>
      <ref url="http://securityreason.com/securityalert/2128" source="SREASON">2128</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="pml_driver_hpz12">
        <vers num=""/>
      </prod>
      <prod vendor="hp" name="color_laserjet_4650">
        <vers num=""/>
      </prod>
      <prod vendor="hp" name="officejet_4100">
        <vers num=""/>
      </prod>
      <prod vendor="hp" name="officejet_5100">
        <vers num=""/>
      </prod>
      <prod vendor="hp" name="officejet_5500">
        <vers num=""/>
      </prod>
      <prod vendor="hp" name="officejet_6100">
        <vers num=""/>
      </prod>
      <prod vendor="hp" name="officejet_7100">
        <vers num=""/>
      </prod>
      <prod vendor="hp" name="officejet_d">
        <vers num=""/>
      </prod>
      <prod vendor="hp" name="officejet_g">
        <vers num=""/>
      </prod>
      <prod vendor="hp" name="officejet_k">
        <vers num=""/>
      </prod>
      <prod vendor="hp" name="psc_1100">
        <vers num=""/>
      </prod>
      <prod vendor="hp" name="psc_1200">
        <vers num=""/>
      </prod>
      <prod vendor="hp" name="psc_1210_all-in-one">
        <vers num=""/>
      </prod>
      <prod vendor="hp" name="psc_1300">
        <vers num=""/>
      </prod>
      <prod vendor="hp" name="psc_2100">
        <vers num=""/>
      </prod>
      <prod vendor="hp" name="psc_2200">
        <vers num=""/>
      </prod>
      <prod vendor="hp" name="psc_2400_photosmart_all-in-one">
        <vers num=""/>
      </prod>
      <prod vendor="hp" name="psc_2500_photosmart_all-in-one">
        <vers num=""/>
      </prod>
      <prod vendor="hp" name="psc_2510_photosmart">
        <vers num=""/>
      </prod>
      <prod vendor="hp" name="psc_700">
        <vers num=""/>
      </prod>
      <prod vendor="hp" name="psc_900">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0162" published="2007-01-09" name="CVE-2007-0162" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unsanity Application Enhancer (APE) 2.0.2 installs with insecure permissions for the (1) ApplicationEnhancer binary and the (2) /Library/Frameworks/ApplicationEnhancer.framework directory, which allows local users to gain privileges by modifying or replacing the binary or library files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://projects.info-pull.com/moab/MOAB-08-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-08-01-2007.html</ref>
      <ref url="http://osvdb.org/32661" source="OSVDB">32661</ref>
      <ref url="http://landonf.bikemonkey.org/code/macosx/MOAB_Day_8.20070109002959.18582.timor.html" source="MISC" adv="1">http://landonf.bikemonkey.org/code/macosx/MOAB_Day_8.20070109002959.18582.timor.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31349" source="XF">ape-appenhancer-privilege-escalation(31349)</ref>
      <ref url="http://www.securityfocus.com/bid/21951" source="BID">21951</ref>
      <ref url="http://secunia.com/advisories/23649" source="SECUNIA">23649</ref>
    </refs>
    <vuln_soft>
      <prod vendor="unsanity" name="application_enhancer">
        <vers num="2.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0163" published="2007-01-09" name="CVE-2007-0163" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">SecureKit Steganography 1.7.1 and 1.8 embeds password information in the carrier file, which allows remote attackers to bypass authentication requirements and decrypt embedded steganography by replacing the last 20 bytes of the JPEG image with alternate password information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456283/100/0/threaded" source="BUGTRAQ">20070106 Cracking Steganography Application in less than ONE minute</ref>
      <ref url="http://secunia.com/advisories/23639" source="SECUNIA" adv="1">23639</ref>
      <ref url="http://osvdb.org/31244" source="OSVDB">31244</ref>
      <ref url="http://homepage.mac.com/adonismac/Advisory/steg/steganography.html" source="MISC" adv="1">http://homepage.mac.com/adonismac/Advisory/steg/steganography.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31378" source="XF">steganography-password-security-bypass(31378)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456519/100/0/threaded" source="BUGTRAQ">20070107 A Major design Bug in Steganography 1.7.x, 1.8 (latest) (Updated Version)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="securekit" name="securekit_steganography">
        <vers num="1.7.1"/>
        <vers num="1.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0164" published="2007-01-09" name="CVE-2007-0164" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Camouflage 1.2.1 embeds password information in the carrier file, which allows remote attackers to bypass authentication requirements and decrypt embedded steganography by replacing certain bytes of the JPEG image with alternate password information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21939" source="BID">21939</ref>
      <ref url="http://secunia.com/advisories/23578" source="SECUNIA" adv="1">23578</ref>
      <ref url="http://osvdb.org/32651" source="OSVDB">32651</ref>
      <ref url="http://homepage.mac.com/adonismac/Advisory/steg/camouflage.html" source="MISC" adv="1">http://homepage.mac.com/adonismac/Advisory/steg/camouflage.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31375" source="XF">camouflage-password-security-bypass(31375)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456541/100/0/threaded" source="BUGTRAQ">20070107 A Major design Bug in Camouflage 1.2.1 (latest)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="camouflage" name="camouflage">
        <vers num="1.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0165" published="2007-01-09" name="CVE-2007-0165" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in libnsl in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (crash) via malformed RPC requests that trigger a crash in rpcbind.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102713-1" source="SUNALERT" patch="1" adv="1">102713</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0110" source="VUPEN">ADV-2007-0110</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5920" source="OVAL">oval:org.mitre.oval:def:5920</ref>
      <ref url="http://osvdb.org/31576" source="OSVDB">31576</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31366" source="XF">solaris-rpcbind-dos(31366)</ref>
      <ref url="http://www.securityfocus.com/bid/21964" source="BID">21964</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-036.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-036.htm</ref>
      <ref url="http://securitytracker.com/id?1017492" source="SECTRACK">1017492</ref>
      <ref url="http://secunia.com/advisories/24056" source="SECUNIA">24056</ref>
      <ref url="http://secunia.com/advisories/23700" source="SECUNIA">23700</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2210" source="OVAL" sig="1">oval:org.mitre.oval:def:2210</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0166" published="2007-01-11" name="CVE-2007-0166" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.7" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">The jail rc.d script in FreeBSD 5.3 up to 6.2 does not verify pathnames when writing to /var/log/console.log during a jail start-up, or when file systems are mounted or unmounted, which allows local root users to overwrite arbitrary files, or mount/unmount files, outside of the jail via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://security.freebsd.org/advisories/FreeBSD-SA-07:01.jail.asc" source="FREEBSD" adv="1">FreeBSD-SA-07:01</ref>
      <ref url="http://osvdb.org/32726" source="OSVDB">32726</ref>
      <ref url="http://www.securityfocus.com/bid/22011" source="BID">22011</ref>
      <ref url="http://securitytracker.com/id?1017505" source="SECTRACK">1017505</ref>
      <ref url="http://secunia.com/advisories/23730" source="SECUNIA">23730</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="5.3"/>
        <vers prev="1" num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0167" published="2007-01-09" name="CVE-2007-0167" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP file inclusion vulnerabilities in WGS-PPC (aka PPC Search Engine), as distributed with other aliases, allow remote attackers to execute arbitrary PHP code via a URL in the INC parameter in (1) config_admin.php, (2) config_main.php, (3) config_member.php, and (4) mysql_config.php in config/; (5) admin.php and (6) index.php in admini/; (7) paypalipn/ipnprocess.php; (8) index.php and (9) registration.php in members/; and (10) ppcbannerclick.php and (11) ppcclick.php in main/.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21961" source="BID">21961</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456386/100/0/threaded" source="BUGTRAQ" adv="1">20070109 ppc engine Multiple file inclusion</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001221.html" source="VIM">20070109 "ppc engine" is WGS-PPC</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31355" source="XF">demoppc-inc-file-include(31355)</ref>
      <ref url="http://www.osvdb.org/33454" source="OSVDB">33454</ref>
      <ref url="http://www.osvdb.org/33453" source="OSVDB">33453</ref>
      <ref url="http://www.osvdb.org/33452" source="OSVDB">33452</ref>
      <ref url="http://www.osvdb.org/33451" source="OSVDB">33451</ref>
      <ref url="http://www.osvdb.org/33450" source="OSVDB">33450</ref>
      <ref url="http://www.osvdb.org/33449" source="OSVDB">33449</ref>
      <ref url="http://www.osvdb.org/33448" source="OSVDB">33448</ref>
      <ref url="http://www.osvdb.org/33447" source="OSVDB">33447</ref>
      <ref url="http://www.osvdb.org/33446" source="OSVDB">33446</ref>
      <ref url="http://www.osvdb.org/33445" source="OSVDB">33445</ref>
      <ref url="http://www.osvdb.org/33444" source="OSVDB">33444</ref>
      <ref url="http://securityreason.com/securityalert/2134" source="SREASON">2134</ref>
      <ref url="http://milw0rm.com/exploits/3104" source="MILW0RM">3104</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ppc_search_engine" name="ppc_search_engine">
        <vers num="1.61"/>
      </prod>
      <prod vendor="wgs-ppc" name="wgs-ppc">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0168" published="2007-01-11" name="CVE-2007-0168" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Tape Engine service in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allows remote attackers to execute arbitrary code via certain data in opnum 0xBF in an RPC request, which is directly executed.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/662400" source="CERT-VN">VU#662400</ref>
      <ref url="http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp" source="CONFIRM" patch="1">http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-002.html" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-07-002.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0154" source="VUPEN">ADV-2007-0154</ref>
      <ref url="http://osvdb.org/31327" source="OSVDB">31327</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31442" source="XF">brightstor-tapeengine-code-execution(31442)</ref>
      <ref url="http://www.securityfocus.com/bid/22010" source="BID">22010</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456616/100/0/threaded" source="BUGTRAQ">20070111 ZDI-07-002: CA BrightStor ARCserve Backup Tape Engine Code Execution Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/456711" source="BUGTRAQ">20070111 [CAID 34955, 34956, 34957, 34958, 34959, 34817]: CA BrightStor ARCserve Backup Multiple Overflow Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/456637" source="BUGTRAQ">20070111 LS-20061002 - Computer Associates BrightStor ARCserve Backup Remote Code Execution Vulnerability</ref>
      <ref url="http://www.lssec.com/advisories/LS-20061002.pdf" source="MISC">http://www.lssec.com/advisories/LS-20061002.pdf</ref>
      <ref url="http://securitytracker.com/id?1017506" source="SECTRACK">1017506</ref>
      <ref url="http://secunia.com/advisories/23648" source="SECUNIA">23648</ref>
      <ref url="http://livesploit.com/advisories/LS-20061002.pdf" source="MISC">http://livesploit.com/advisories/LS-20061002.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="brightstor_arcserve_backup">
        <vers prev="1" num="11.5"/>
        <vers num="9.01"/>
      </prod>
      <prod vendor="ca" name="brightstor_enterprise_backup">
        <vers num="10.5"/>
      </prod>
      <prod vendor="ca" name="business_protection_suite">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0169" published="2007-01-11" name="CVE-2007-0169" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allow remote attackers to execute arbitrary code via RPC requests with crafted data for opnums (1) 0x2F and (2) 0x75 in the (a) Message Engine RPC service, or opnum (3) 0xCF in the Tape Engine service.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/180336" source="CERT-VN">VU#180336</ref>
      <ref url="http://www.kb.cert.org/vuls/id/151032" source="CERT-VN">VU#151032</ref>
      <ref url="http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp" source="CONFIRM" patch="1">http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31443" source="XF">brightstor-messageengine-rpc-bo(31443)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31433" source="XF">brightstor-tapeengine-rpc-bo(31433)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-004.html" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-07-004.html</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-003.html" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-07-003.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0154" source="VUPEN" adv="1">ADV-2007-0154</ref>
      <ref url="http://www.securityfocus.com/bid/22006" source="BID">22006</ref>
      <ref url="http://www.securityfocus.com/bid/22005" source="BID">22005</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456619/100/0/threaded" source="BUGTRAQ">20070111 ZDI-07-003: CA BrightStor ARCserve Backup Message Engine Buffer Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456618/100/0/threaded" source="BUGTRAQ">20070111 ZDI-07-004: CA BrightStor ARCserve Backup Tape Engine Buffer Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/456711" source="BUGTRAQ">20070111 [CAID 34955, 34956, 34957, 34958, 34959, 34817]: CA BrightStor ARCserve Backup Multiple Overflow Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1017506" source="SECTRACK">1017506</ref>
      <ref url="http://secunia.com/advisories/23648" source="SECUNIA" adv="1">23648</ref>
      <ref url="http://osvdb.org/31327" source="OSVDB">31327</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=467" source="IDEFENSE">20070111 Computer Associates BrightStor ARCserve Backup RPC Engine PFC Request Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="brightstor_arcserve_backup">
        <vers prev="1" num="11.5"/>
        <vers num="9.01"/>
      </prod>
      <prod vendor="ca" name="brightstor_enterprise_backup">
        <vers num="10.5"/>
      </prod>
      <prod vendor="ca" name="business_protection_suite">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0170" published="2007-01-10" name="CVE-2007-0170" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in AllMyVisitors 0.4.0 allows remote attackers to execute arbitrary PHP code via a URL in the AMV_serverpath parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31316" source="XF">allmyvisitors-index-file-include(31316)</ref>
      <ref url="http://www.securityfocus.com/bid/21917" source="BID">21917</ref>
      <ref url="http://osvdb.org/35904" source="OSVDB">35904</ref>
      <ref url="http://milw0rm.com/exploits/3097" source="MILW0RM">3097</ref>
    </refs>
    <vuln_soft>
      <prod vendor="allmyphp" name="allmyvisitors">
        <vers num="0.4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0171" published="2007-01-10" name="CVE-2007-0171" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in AllMyLinks 0.5.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AML_opensite parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31314" source="XF" adv="1">allmylinks-index-file-include(31314)</ref>
      <ref url="http://www.securityfocus.com/bid/21916" source="BID" adv="1">21916</ref>
      <ref url="http://osvdb.org/35909" source="OSVDB">35909</ref>
      <ref url="http://milw0rm.com/exploits/3096" source="MILW0RM">3096</ref>
    </refs>
    <vuln_soft>
      <prod vendor="voice_of_web" name="allmylinks">
        <vers num="0.4"/>
        <vers num="0.4.1"/>
        <vers num="0.4.3"/>
        <vers num="0.4.4"/>
        <vers num="0.4.9"/>
        <vers num="0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0172" published="2007-01-10" name="CVE-2007-0172" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.3.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the AMG_serverpath parameter to (1) comments.php and (2) signin.php; and possibly via a URL in unspecified parameters to (3) include/submit.inc.php, (4) admin/index.php, (5) include/cm_submit.inc.php, and (6) index.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31310" source="XF" adv="1">allmyguests-multiple-file-include(31310)</ref>
      <ref url="http://www.securityfocus.com/bid/21918" source="BID" adv="1">21918</ref>
      <ref url="http://osvdb.org/35923" source="OSVDB">35923</ref>
      <ref url="http://osvdb.org/35921" source="OSVDB">35921</ref>
      <ref url="http://osvdb.org/35919" source="OSVDB">35919</ref>
      <ref url="http://osvdb.org/35917" source="OSVDB">35917</ref>
      <ref url="http://osvdb.org/35916" source="OSVDB">35916</ref>
      <ref url="http://osvdb.org/35915" source="OSVDB">35915</ref>
      <ref url="http://milw0rm.com/exploits/3093" source="MILW0RM">3093</ref>
    </refs>
    <vuln_soft>
      <prod vendor="voice_of_web" name="allmyguests">
        <vers prev="1" num="0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0173" published="2007-01-10" name="CVE-2007-0173" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in L2J Statistik Script 0.09 and earlier, when register_globals is enabled and magic_quotes is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31309" source="XF" adv="1">l2j-statistik-index-file-include(31309)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0097" source="VUPEN">ADV-2007-0097</ref>
      <ref url="http://www.securityfocus.com/bid/21914" source="BID" adv="1">21914</ref>
      <ref url="http://osvdb.org/35914" source="OSVDB">35914</ref>
      <ref url="http://milw0rm.com/exploits/3091" source="MILW0RM">3091</ref>
    </refs>
    <vuln_soft>
      <prod vendor="l2j" name="statistik_script">
        <vers num="0.09"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0174" published="2007-01-10" name="CVE-2007-0174" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple stack-based multiple buffer overflows in the BRWOSSRE2UC.dll ActiveX Control in Sina UC2006 and earlier allow remote attackers to execute arbitrary code via a long string in the (1) astrVerion parameter to the SendChatRoomOpt function or (2) the astrDownDir parameter to the SendDownLoadFile function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0093" source="VUPEN">ADV-2007-0093</ref>
      <ref url="http://secway.org/advisory/ad20070109EN.txt" source="MISC" adv="1">http://secway.org/advisory/ad20070109EN.txt</ref>
      <ref url="http://secunia.com/advisories/23638" source="SECUNIA" adv="1">23638</ref>
      <ref url="http://osvdb.org/32659" source="OSVDB">32659</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=116832852700467&amp;w=2" source="FULLDISC">20070109 Sina UC ActiveX Multiple Remote Stack Overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31350" source="XF">sinauc-senddownloadfile-bo(31350)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31348" source="XF">sinauc-sendchatroomopt-bo(31348)</ref>
      <ref url="http://www.securityfocus.com/bid/21958" source="BID">21958</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456378/100/0/threaded" source="BUGTRAQ">20070109 Sina UC ActiveX Multiple Remote Stack Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sina" name="sina">
        <vers num="uc2006"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0175" published="2007-01-10" name="CVE-2007-0175" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in htsrv/login.php in b2evolution 1.8.6 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes in the redirect_to parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31368" source="XF">b2evolution-login-xss(31368)</ref>
      <ref url="http://www.securityfocus.com/bid/21953" source="BID">21953</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1568" source="DEBIAN">DSA-1568</ref>
      <ref url="http://secunia.com/advisories/30093" source="SECUNIA">30093</ref>
      <ref url="http://secunia.com/advisories/23656" source="SECUNIA" adv="1">23656</ref>
      <ref url="http://osvdb.org/32027" source="OSVDB">32027</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=410568" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=410568</ref>
    </refs>
    <vuln_soft>
      <prod vendor="b2evolution" name="b2evolution">
        <vers num="1.8.2"/>
        <vers num="1.8.5"/>
        <vers num="1.8.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0176" published="2007-01-10" name="CVE-2007-0176" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web script or HTML via the words parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21946" source="BID" adv="1">21946</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456296/100/0/threaded" source="BUGTRAQ" adv="1">20070108 GForge Cross Site Scripting vulnerability</ref>
      <ref url="http://www.eazel.es/advisory006-gforge-cross-site-scripting-vulnerability.html" source="MISC" adv="1">http://www.eazel.es/advisory006-gforge-cross-site-scripting-vulnerability.html</ref>
      <ref url="http://securitytracker.com/id?1017482" source="SECTRACK" adv="1">1017482</ref>
      <ref url="http://secunia.com/advisories/23675" source="SECUNIA" adv="1">23675</ref>
      <ref url="http://osvdb.org/31248" source="OSVDB">31248</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31346" source="XF">gforge-words-xss(31346)</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1475" source="DEBIAN">DSA-1475</ref>
      <ref url="http://securityreason.com/securityalert/2133" source="SREASON">2133</ref>
      <ref url="http://secunia.com/advisories/28598" source="SECUNIA">28598</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gforge" name="gforge">
        <vers num="4.5.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0177" published="2007-01-10" name="CVE-2007-0177" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the AJAX module in MediaWiki before 1.6.9, 1.7 before 1.7.2, 1.8 before 1.8.3, and 1.9 before 1.9.0rc2, when wgUseAjax is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21956" source="BID" patch="1" adv="1">21956</ref>
      <ref url="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_0RC2/phase3/RELEASE-NOTES" source="CONFIRM" patch="1" adv="1">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_0RC2/phase3/RELEASE-NOTES</ref>
      <ref url="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_8_3/phase3/RELEASE-NOTES" source="CONFIRM" patch="1" adv="1">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_8_3/phase3/RELEASE-NOTES</ref>
      <ref url="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_7_2/phase3/RELEASE-NOTES" source="CONFIRM" patch="1" adv="1">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_7_2/phase3/RELEASE-NOTES</ref>
      <ref url="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_6_9/phase3/RELEASE-NOTES" source="CONFIRM" patch="1" adv="1">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_6_9/phase3/RELEASE-NOTES</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=652721" source="CONFIRM" patch="1" adv="1">http://sourceforge.net/forum/forum.php?forum_id=652721</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0096" source="VUPEN">ADV-2007-0096</ref>
      <ref url="http://secunia.com/advisories/23647" source="SECUNIA" adv="1">23647</ref>
      <ref url="http://osvdb.org/31525" source="OSVDB">31525</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31359" source="XF">mediawiki-ajax-unspecified-xss(31359)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_6_sr.html" source="SUSE">SUSE-SR:2007:006</ref>
      <ref url="http://secunia.com/advisories/24889" source="SECUNIA">24889</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
        <vers num="1.6.5"/>
        <vers num="1.6.5_r14348"/>
        <vers num="1.6.6"/>
        <vers num="1.7.0"/>
        <vers num="1.7.1"/>
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.9.0" edition="rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0178" published="2007-01-10" name="CVE-2007-0178" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in info.php in Easy Banner Pro 2.8 allows remote attackers to execute arbitrary PHP code via a URL in the s[phppath] parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456404/100/0/threaded" source="BUGTRAQ">20070108 Easy Banner Pro Version 2.8 &lt;= Remote File Inclusion</ref>
      <ref url="http://osvdb.org/33455" source="OSVDB">33455</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31374" source="XF">easybannerpro-info-file-include(31374)</ref>
      <ref url="http://www.securityfocus.com/bid/21967" source="BID">21967</ref>
      <ref url="http://securityreason.com/securityalert/2132" source="SREASON">2132</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_web_scripts" name="easy_banner_pro">
        <vers num="2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0179" published="2007-01-10" name="CVE-2007-0179" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in comment.php in PHPKIT 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the subid parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21962" source="BID">21962</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456384/100/0/threaded" source="BUGTRAQ">20070109 Re: PHPKit 1.6.1 RC2 (faq/faq.php) Remote SQL Injection Exploit</ref>
      <ref url="http://osvdb.org/31266" source="OSVDB">31266</ref>
      <ref url="http://securityreason.com/securityalert/2131" source="SREASON">2131</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpkit" name="phpkit">
        <vers num="1.6.1" edition="rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0180" published="2007-01-10" name="CVE-2007-0180" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Stack-based buffer overflow in EF Commander 5.75 allows user-assisted attackers to execute arbitrary code via a crafted ISO file containing a file within several nested directories, which produces a large filename that triggers the overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://vuln.sg/efcommander575-en.html" source="MISC" patch="1" adv="1">http://vuln.sg/efcommander575-en.html</ref>
      <ref url="http://secunia.com/advisories/23659" source="SECUNIA" patch="1" adv="1">23659</ref>
      <ref url="http://osvdb.org/32660" source="OSVDB">32660</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31365" source="XF">efcommander-iso-pathname-bo(31365)</ref>
      <ref url="http://www.securityfocus.com/bid/21969" source="BID">21969</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ef_software" name="ef_commander">
        <vers num="5.75"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0181" published="2007-01-10" name="CVE-2007-0181" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in include/common_function.php in magic photo storage website allows remote attackers to execute arbitrary PHP code via a URL in the _config[site_path] parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0136" source="VUPEN">ADV-2007-0136</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456264/100/0/threaded" source="BUGTRAQ">20070108 magic photo storage website Remote File Inclusion</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31347" source="XF">magicphotostorage-config-file-include(31347)</ref>
      <ref url="http://www.securityfocus.com/bid/21965" source="BID">21965</ref>
      <ref url="http://secunia.com/advisories/23687" source="SECUNIA">23687</ref>
      <ref url="http://milw0rm.com/exploits/3100" source="MILW0RM">3100</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scriptaty" name="magic_photo_storage_website">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0182" published="2007-01-12" name="CVE-2007-0182" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbitrary PHP code via a URL in the _config[site_path] parameter to (1) admin_password.php, (2) add_welcome_text.php, (3) admin_email.php, (4) add_templates.php, (5) admin_paypal_email.php, (6) approve_member.php, (7) delete_member.php, (8) index.php, (9) list_members.php, (10) membership_pricing.php, or (11) send_email.php in admin/; (12) config.php or (13) db_config.php in include/; or (14) add_category.php, (15) add_news.php, (16) change_catalog_template.php, (17) couple_milestone.php, (18) couple_profile.php, (19) delete_category.php, (20) index.php, (21) login.php, (22) logout.php, (23) register.php, (24) upload_photo.php, (25) user_catelog_password.php, (26) user_email.php, (27) user_extend.php, or (28) user_membership_password.php in user/.  NOTE: the include/common_function.php vector is already covered by another candidate from the same date.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456389/100/0/threaded" source="BUGTRAQ" adv="1">20070108 magic photo storage website Multiple Remote File Inclusion</ref>
      <ref url="http://www.securityfocus.com/bid/21965" source="BID">21965</ref>
      <ref url="http://www.osvdb.org/33439" source="OSVDB">33439</ref>
      <ref url="http://www.osvdb.org/33438" source="OSVDB">33438</ref>
      <ref url="http://www.osvdb.org/33437" source="OSVDB">33437</ref>
      <ref url="http://www.osvdb.org/33436" source="OSVDB">33436</ref>
      <ref url="http://www.osvdb.org/33435" source="OSVDB">33435</ref>
      <ref url="http://www.osvdb.org/33434" source="OSVDB">33434</ref>
      <ref url="http://www.osvdb.org/33433" source="OSVDB">33433</ref>
      <ref url="http://www.osvdb.org/33432" source="OSVDB">33432</ref>
      <ref url="http://www.osvdb.org/33431" source="OSVDB">33431</ref>
      <ref url="http://www.osvdb.org/33430" source="OSVDB">33430</ref>
      <ref url="http://www.osvdb.org/33429" source="OSVDB">33429</ref>
      <ref url="http://www.osvdb.org/33428" source="OSVDB">33428</ref>
      <ref url="http://www.osvdb.org/33427" source="OSVDB">33427</ref>
      <ref url="http://www.osvdb.org/33426" source="OSVDB">33426</ref>
      <ref url="http://www.osvdb.org/33425" source="OSVDB">33425</ref>
      <ref url="http://www.osvdb.org/33423" source="OSVDB">33423</ref>
      <ref url="http://www.osvdb.org/33422" source="OSVDB">33422</ref>
      <ref url="http://www.osvdb.org/33421" source="OSVDB">33421</ref>
      <ref url="http://www.osvdb.org/33420" source="OSVDB">33420</ref>
      <ref url="http://www.osvdb.org/33419" source="OSVDB">33419</ref>
      <ref url="http://www.osvdb.org/33418" source="OSVDB">33418</ref>
      <ref url="http://www.osvdb.org/33417" source="OSVDB">33417</ref>
      <ref url="http://www.osvdb.org/33416" source="OSVDB">33416</ref>
      <ref url="http://www.osvdb.org/33415" source="OSVDB">33415</ref>
      <ref url="http://www.osvdb.org/33414" source="OSVDB">33414</ref>
      <ref url="http://www.osvdb.org/33413" source="OSVDB">33413</ref>
      <ref url="http://www.osvdb.org/33412" source="OSVDB">33412</ref>
      <ref url="http://www.osvdb.org/33411" source="OSVDB">33411</ref>
      <ref url="http://www.osvdb.org/32668" source="OSVDB">32668</ref>
      <ref url="http://securityreason.com/securityalert/2136" source="SREASON">2136</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scriptaty" name="magic_photo_storage_website">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0183" published="2007-01-12" name="CVE-2007-0183" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrary web script or HTML via the NS-max-records parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21977" source="BID" patch="1" adv="1">21977</ref>
      <ref url="http://secunia.com/advisories/23605" source="SECUNIA" patch="1" adv="1">23605</ref>
      <ref url="http://osvdb.org/32662" source="OSVDB">32662</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="iplanet_web_server">
        <vers num="4.1" edition="sp1"/>
        <vers num="4.1" edition="sp1:enterprise"/>
        <vers num="4.1" edition="sp10"/>
        <vers num="4.1" edition="sp10:enterprise"/>
        <vers num="4.1" edition="sp2"/>
        <vers num="4.1" edition="sp2:enterprise"/>
        <vers num="4.1" edition="sp3"/>
        <vers num="4.1" edition="sp3:enterprise"/>
        <vers num="4.1" edition="sp4"/>
        <vers num="4.1" edition="sp4:enterprise"/>
        <vers num="4.1" edition="sp5"/>
        <vers num="4.1" edition="sp5:enterprise"/>
        <vers num="4.1" edition="sp6"/>
        <vers num="4.1" edition="sp6:enterprise"/>
        <vers num="4.1" edition="sp7"/>
        <vers num="4.1" edition="sp7:enterprise"/>
        <vers num="4.1" edition="sp8"/>
        <vers num="4.1" edition="sp8:enterprise"/>
        <vers num="4.1" edition="sp9"/>
        <vers num="4.1" edition="sp9:enterprise"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0184" published="2007-01-12" name="CVE-2007-0184" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Getahead Direct Web Remoting (DWR) before 1.1.4 allows attackers to obtain unauthorized access to public methods via a crafted request that bypasses the include/exclude checks.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0095" source="VUPEN">ADV-2007-0095</ref>
      <ref url="http://www.securityfocus.com/bid/21955" source="BID">21955</ref>
      <ref url="http://secunia.com/advisories/23641" source="SECUNIA" adv="1">23641</ref>
      <ref url="http://osvdb.org/32657" source="OSVDB">32657</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html" source="SUSE">SUSE-SR:2009:004</ref>
      <ref url="http://getahead.ltd.uk/dwr/changelog" source="CONFIRM">http://getahead.ltd.uk/dwr/changelog</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31377" source="XF">dwr-include-exclude-security-bypass(31377)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="getahead" name="direct_web_remoting">
        <vers num="0.7"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers prev="1" num="1.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0185" published="2007-01-12" name="CVE-2007-0185" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Getahead Direct Web Remoting (DWR) before 1.1.4 allows attackers to cause a denial of service (memory exhaustion and servlet outage) via unknown vectors related to a large number of calls in a batch.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23641" source="SECUNIA" patch="1" adv="1">23641</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0095" source="VUPEN">ADV-2007-0095</ref>
      <ref url="http://www.securityfocus.com/bid/21955" source="BID">21955</ref>
      <ref url="http://osvdb.org/32658" source="OSVDB">32658</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html" source="SUSE">SUSE-SR:2009:004</ref>
      <ref url="http://getahead.ltd.uk/dwr/changelog" source="CONFIRM">http://getahead.ltd.uk/dwr/changelog</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31382" source="XF">dwr-servlet-engine-dos(31382)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="getahead" name="direct_web_remoting">
        <vers num="0.7"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers prev="1" num="1.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0186" published="2007-01-12" name="CVE-2007-0186" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL VPN allow remote attackers to inject arbitrary web script or HTML via (1) the xcho parameter to my.logon.php3; the (2) topblue, (3) midblue, (4) wtopblue, and certain other Custom color parameters in a per action to vdesk/admincon/index.php; the (5) h321, (6) h311, (7) h312, and certain other Front Door custom text color parameters in a per action to vdesk/admincon/index.php; the (8) ua parameter in a bro action to vdesk/admincon/index.php; the (9) app_param and (10) app_name parameters to webyfiers.php; (11) double eval functions; (12) JavaScript contained in an &lt;FP_DO_NOT_TOUCH> element; and (13) the vhost parameter to my.activation.php.  NOTE: it is possible that this candidate overlaps CVE-2006-3550.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://tech.f5.com/home/solutions/sol6920.html" source="CONFIRM">https://tech.f5.com/home/solutions/sol6920.html</ref>
      <ref url="https://tech.f5.com/home/solutions/sol6919.html" source="CONFIRM">https://tech.f5.com/home/solutions/sol6919.html</ref>
      <ref url="http://www.securityfocus.com/bid/21957" source="BID">21957</ref>
      <ref url="http://www.mnin.org/advisories/2007_firepass.pdf" source="MISC">http://www.mnin.org/advisories/2007_firepass.pdf</ref>
      <ref url="http://secunia.com/advisories/23643" source="SECUNIA">23643</ref>
      <ref url="http://secunia.com/advisories/23627" source="SECUNIA">23627</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051651.html" source="FULLDISC">20070106 NNL-Labs &amp; MNIN - F5 FirePass Security Advisory</ref>
      <ref url="http://www.osvdb.org/32743" source="OSVDB">32743</ref>
      <ref url="http://www.osvdb.org/32742" source="OSVDB">32742</ref>
      <ref url="http://www.osvdb.org/32741" source="OSVDB">32741</ref>
      <ref url="http://www.osvdb.org/32740" source="OSVDB">32740</ref>
      <ref url="http://www.osvdb.org/32739" source="OSVDB">32739</ref>
      <ref url="http://www.osvdb.org/32738" source="OSVDB">32738</ref>
      <ref url="http://www.osvdb.org/32737" source="OSVDB">32737</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f5" name="firepass_4100">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0187" published="2007-01-12" name="CVE-2007-0187" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">F5 FirePass 5.4 through 5.5.2 and 6.0 allows remote attackers to access restricted URLs via (1) a trailing null byte, (2) multiple leading slashes, (3) Unicode encoding, (4) URL-encoded directory traversal or same-directory characters, or (5) upper case letters in the domain name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://tech.f5.com/home/solutions/sol6924.html" source="CONFIRM">https://tech.f5.com/home/solutions/sol6924.html</ref>
      <ref url="http://www.securityfocus.com/bid/21957" source="BID">21957</ref>
      <ref url="http://www.mnin.org/advisories/2007_firepass.pdf" source="MISC">http://www.mnin.org/advisories/2007_firepass.pdf</ref>
      <ref url="http://osvdb.org/39167" source="OSVDB">39167</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0141.html" source="FULLDISC">20070105 NNL-Labs &amp; MNIN - F5 FirePass Security Advisory</ref>
      <ref url="https://tech.f5.com/home/solutions/sol6916.html" source="CONFIRM">https://tech.f5.com/home/solutions/sol6916.html</ref>
      <ref url="http://secunia.com/advisories/23640" source="SECUNIA">23640</ref>
      <ref url="http://secunia.com/advisories/23626" source="SECUNIA">23626</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051651.html" source="FULLDISC">20070106 NNL-Labs &amp; MNIN - F5 FirePass Security Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f5" name="firepass">
        <vers num="5.4"/>
        <vers num="5.4.1"/>
        <vers num="5.4.2"/>
        <vers num="5.4.3"/>
        <vers num="5.4.4"/>
        <vers num="5.4.5"/>
        <vers num="5.4.6"/>
        <vers num="5.4.7"/>
        <vers num="5.4.8"/>
        <vers num="5.4.9"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.5.2"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0188" published="2007-01-12" name="CVE-2007-0188" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">F5 FirePass 5.4 through 5.5.1 does not properly enforce host access restrictions when a client uses a single integer (dword) representation of an IP address ("dotless IP address"), which allows remote authenticated users to connect to the FirePass administrator console and certain other network resources.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://tech.f5.com/home/solutions/sol6922.html" source="CONFIRM">https://tech.f5.com/home/solutions/sol6922.html</ref>
      <ref url="http://www.securityfocus.com/bid/21957" source="BID">21957</ref>
      <ref url="http://www.mnin.org/advisories/2007_firepass.pdf" source="MISC">http://www.mnin.org/advisories/2007_firepass.pdf</ref>
      <ref url="http://www.osvdb.org/32734" source="OSVDB">32734</ref>
      <ref url="http://secunia.com/advisories/23640" source="SECUNIA">23640</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051651.html" source="FULLDISC">20070106 NNL-Labs &amp; MNIN - F5 FirePass Security Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f5" name="firepass">
        <vers num="5.4"/>
        <vers num="5.4.1"/>
        <vers num="5.4.2"/>
        <vers num="5.4.3"/>
        <vers num="5.4.4"/>
        <vers num="5.4.5"/>
        <vers num="5.4.6"/>
        <vers num="5.4.7"/>
        <vers num="5.4.8"/>
        <vers num="5.4.9"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.5.2"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0189" published="2007-01-12" name="CVE-2007-0189" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in index.php in GeoBB Georgian Bulletin Board allows remote attackers to execute arbitrary PHP code via a URL in the action parameter.  NOTE: CVE disputes this issue, since GeoBB 1.0 sets $action to a whitelisted value.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31335" source="XF">geobb-index-file-include(31335)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456251/100/0/threaded" source="BUGTRAQ">20070107 GeoBB Georgian Bulletin Board Remote File Include Vuln.</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001230.html" source="VIM">20070110 Dispute of GeoBB RFI</ref>
      <ref url="http://osvdb.org/33440" source="OSVDB">33440</ref>
      <ref url="http://securityreason.com/securityalert/2141" source="SREASON">2141</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geobb" name="georgian_bulletin_board">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0190" published="2007-01-12" name="CVE-2007-0190" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in edit_address.php in edit-x ecommerce allows remote attackers to execute arbitrary PHP code via a URL in the include_dir parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0158" source="VUPEN">ADV-2007-0158</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456439/100/0/threaded" source="BUGTRAQ">20070109 edit-x ecommerce (include_dir) Remote File include</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31384" source="XF">editx-editaddress-file-include(31384)</ref>
      <ref url="http://www.securityfocus.com/bid/21974" source="BID">21974</ref>
      <ref url="http://securityreason.com/securityalert/2139" source="SREASON">2139</ref>
    </refs>
    <vuln_soft>
      <prod vendor="edit-x" name="ecommerce">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0191" published="2007-01-12" name="CVE-2007-0191" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in admin.php in MKPortal allows remote attackers to inject arbitrary web script or HTML via two certain fields in a contents_new operation in the ad_contents section.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31304" source="XF">mkportal-admin-xss(31304)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456042/100/100/threaded" source="BUGTRAQ">20070105 MkPortal Admin XSS</ref>
      <ref url="http://osvdb.org/33399" source="OSVDB">33399</ref>
      <ref url="http://securityreason.com/securityalert/2138" source="SREASON">2138</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mkportal" name="mkportal">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0192" published="2007-01-12" name="CVE-2007-0192" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in the save_main operation in the ad_perms section in admin.php in MKPortal allows remote attackers to modify privilege settings, as demonstrated using a getURL of admin.php within a .swf file contained in an IFRAME element, aka the "All Guests are Admin" attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455894/100/100/threaded" source="BUGTRAQ">20070104 MkPortal "All Guests are Admin" Exploit</ref>
      <ref url="http://osvdb.org/33400" source="OSVDB">33400</ref>
      <ref url="http://securityreason.com/securityalert/2137" source="SREASON">2137</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mkportal" name="mkportal">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0193" published="2007-01-12" name="CVE-2007-0193" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">FON La Fonera routers do not properly limit DNS service access by unauthenticated clients, which allows remote attackers to tunnel traffic via DNS requests for hosts that should not be accessible before authentication.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456344/100/0/threaded" source="BUGTRAQ">20070107 Re: FON Router allows anonymous web access</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456128/100/0/threaded" source="BUGTRAQ">20070106 FON Router allows anonymous web access</ref>
      <ref url="http://osvdb.org/33441" source="OSVDB">33441</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fon" name="la_fonera">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0194" published="2007-01-12" name="CVE-2007-0194" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">admin.php in MKPortal M1.1 RC1 allows remote attackers to obtain sensitive information via a direct request with an MK_PATH=1 query string, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456257/100/0/threaded" source="BUGTRAQ">20070108 MKPortal Full Path Disclosure</ref>
      <ref url="http://osvdb.org/33407" source="OSVDB">33407</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31333" source="XF">mkportal-admin-path-disclosure(31333)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mkportal" name="mkportal">
        <vers num="1.1_rc1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0195" published="2007-01-12" name="CVE-2007-0195" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">my.activation.php3 in F5 FirePass 5.4 through 5.5.1 and 6.0 displays different error messages for failed login attempts with a valid username than for those with an invalid username, which allows remote attackers to confirm the validity of an LDAP account.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://tech.f5.com/home/solutions/sol6923.html" source="CONFIRM">https://tech.f5.com/home/solutions/sol6923.html</ref>
      <ref url="http://www.securityfocus.com/bid/21957" source="BID">21957</ref>
      <ref url="http://www.mnin.org/advisories/2007_firepass.pdf" source="MISC">http://www.mnin.org/advisories/2007_firepass.pdf</ref>
      <ref url="http://www.osvdb.org/32736" source="OSVDB">32736</ref>
      <ref url="http://secunia.com/advisories/23627" source="SECUNIA">23627</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051651.html" source="FULLDISC">20070106 NNL-Labs &amp; MNIN - F5 FirePass Security Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f5" name="firepass">
        <vers num="5.4"/>
        <vers num="5.4.1"/>
        <vers num="5.4.2"/>
        <vers num="5.4.3"/>
        <vers num="5.4.4"/>
        <vers num="5.4.5"/>
        <vers num="5.4.6"/>
        <vers num="5.4.7"/>
        <vers num="5.4.8"/>
        <vers num="5.4.9"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0196" published="2007-01-11" name="CVE-2007-0196" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in admin_check_user.asp in Motionborg Web Real Estate 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (txtUserName parameter) and possibly other parameters.  NOTE: some details were obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31360" source="XF">motionborg-admincheckuser-sql-injection(31360)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0143" source="VUPEN" adv="1">ADV-2007-0143</ref>
      <ref url="http://www.securityfocus.com/bid/21963" source="BID">21963</ref>
      <ref url="http://secunia.com/advisories/23531" source="SECUNIA" adv="1">23531</ref>
      <ref url="http://osvdb.org/32718" source="OSVDB">32718</ref>
      <ref url="http://milw0rm.com/exploits/3105" source="MILW0RM">3105</ref>
    </refs>
    <vuln_soft>
      <prod vendor="motionborg" name="motionborg_web_real_estate">
        <vers prev="1" num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0197" published="2007-01-11" name="CVE-2007-0197" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a long volume name in a DMG disk image, which results in memory corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-047A.html" source="CERT">TA07-047A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/240880" source="CERT-VN">VU#240880</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31410" source="XF">macos-finder-dos(31410)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0140" source="VUPEN">ADV-2007-0140</ref>
      <ref url="http://www.securitytracker.com/id?1017662" source="SECTRACK">1017662</ref>
      <ref url="http://www.securityfocus.com/bid/21980" source="BID">21980</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456578/100/0/threaded" source="BUGTRAQ">20070111 DMA[2007-0107a] OmniWeb Javascript Alert Format String Vulnerabiity and DMA[2007-0109a] Apple Finder Disk Image Volume Label Overflow / DoS</ref>
      <ref url="http://www.osvdb.org/32714" source="OSVDB">32714</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2007-0109a%5D.txt" source="MISC">http://www.digitalmunition.com/DMA%5B2007-0109a%5D.txt</ref>
      <ref url="http://secunia.com/advisories/24198" source="SECUNIA">24198</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-09-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-09-01-2007.html</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html" source="APPLE">APPLE-SA-2007-02-15</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305102" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305102</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.6"/>
        <vers num="10.4.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0198" published="2007-01-11" name="CVE-2007-0198" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The JTapi Gateway process in Cisco Unified Contact Center Enterprise, Unified Contact Center Hosted, IP Contact Center Enterprise, and Cisco IP Contact Center Hosted 5.0 through 7.1 allows remote attackers to cause a denial of service (repeated process restart) via a certain TCP session on the JTapi server port.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070110-jtapi.shtml" source="CISCO" patch="1" adv="1">20070110 Cisco Unified Contact Center and IP Contact Center JTapi Gateway Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0138" source="VUPEN">ADV-2007-0138</ref>
      <ref url="http://www.securityfocus.com/bid/21988" source="BID">21988</ref>
      <ref url="http://osvdb.org/32682" source="OSVDB">32682</ref>
      <ref url="http://securitytracker.com/id?1017499" source="SECTRACK">1017499</ref>
      <ref url="http://secunia.com/advisories/23710" source="SECUNIA">23710</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ip_contact_center_enterprise">
        <vers num="5.0"/>
        <vers prev="1" num="7.1"/>
      </prod>
      <prod vendor="cisco" name="ip_contact_center_hosted">
        <vers num="5.0"/>
        <vers prev="1" num="7.1"/>
      </prod>
      <prod vendor="cisco" name="unified_contact_center_enterprise">
        <vers num="5.0"/>
        <vers prev="1" num="7.1"/>
      </prod>
      <prod vendor="cisco" name="unified_contact_center_hosted">
        <vers num="5.0"/>
        <vers prev="1" num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0199" published="2007-01-11" name="CVE-2007-0199" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Data-link Switching (DLSw) feature in Cisco IOS 11.0 through 12.4 allows remote attackers to cause a denial of service (device reload) via "an invalid value in a DLSw message... during the capabilities exchange."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070110-dlsw.shtml" source="CISCO" patch="1" adv="1">20070110 DLSw Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0139" source="VUPEN">ADV-2007-0139</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5714" source="OVAL">oval:org.mitre.oval:def:5714</ref>
      <ref url="http://osvdb.org/32683" source="OSVDB">32683</ref>
      <ref url="http://www.securityfocus.com/bid/21990" source="BID">21990</ref>
      <ref url="http://securitytracker.com/id?1017498" source="SECTRACK">1017498</ref>
      <ref url="http://secunia.com/advisories/23697" source="SECUNIA">23697</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="11.0"/>
        <vers prev="1" num="12.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0200" published="2007-01-11" name="CVE-2007-0200" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in template.php in Geoffrey Golliher Axiom Photo/News Gallery (axiompng) 0.8.6 allows remote attackers to execute arbitrary PHP code via a URL in the baseAxiomPath parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0107" source="VUPEN">ADV-2007-0107</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001233.html" source="VIM">20070110 source verify - Axiom RFI</ref>
      <ref url="http://osvdb.org/32716" source="OSVDB">32716</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31372" source="XF">axiom-template-file-include(31372)</ref>
      <ref url="http://www.securityfocus.com/bid/21972" source="BID">21972</ref>
      <ref url="http://secunia.com/advisories/23715" source="SECUNIA">23715</ref>
      <ref url="http://milw0rm.com/exploits/3108" source="MILW0RM">3108</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geoffrey_golliher" name="axiom_photo_news_gallery">
        <vers num="0.8.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0201" published="2007-01-11" name="CVE-2007-0201" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the cmd_usr function in ftp-gw in TIS Internet Firewall Toolkit (FWTK) allows remote attackers to execute arbitrary code via a long destination hostname (dest).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31363" source="XF">tisfwtk-ftpgw-bo(31363)</ref>
      <ref url="http://www.securityfocus.com/bid/21960" source="BID">21960</ref>
      <ref url="http://www.ranum.com/security/computer_security/editorials/codetools/" source="MISC" adv="1">http://www.ranum.com/security/computer_security/editorials/codetools/</ref>
      <ref url="http://securitytracker.com/id?1017481" source="SECTRACK">1017481</ref>
      <ref url="http://osvdb.org/35967" source="OSVDB">35967</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tis" name="internet_firewall_toolkit">
        <vers prev="1" num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0202" published="2007-01-11" name="CVE-2007-0202" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in @lex Guestbook 4.0.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the lang parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31393" source="XF">@lexguestbook-index-sql-injection(31393)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0137" source="VUPEN">ADV-2007-0137</ref>
      <ref url="http://www.securityfocus.com/bid/21926" source="BID">21926</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456218/100/0/threaded" source="BUGTRAQ">20070107 @lex Guestbook &lt;= 4.0.2 Remote Command Execution Exploit</ref>
      <ref url="http://secunia.com/advisories/23637" source="SECUNIA" adv="1">23637</ref>
      <ref url="http://osvdb.org/31707" source="OSVDB">31707</ref>
      <ref url="http://acid-root.new.fr/poc/20070107.txt" source="MISC">http://acid-root.new.fr/poc/20070107.txt</ref>
      <ref url="http://securityreason.com/securityalert/2135" source="SREASON">2135</ref>
      <ref url="http://milw0rm.com/exploits/3103" source="MILW0RM">3103</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alexphpteam" name="alex_guestbook">
        <vers num="3.12"/>
        <vers num="3.13"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0203" published="2007-01-11" name="CVE-2007-0203" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in phpMyAdmin before 2.9.2-rc1 have unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0" source="CONFIRM" patch="1" adv="1">http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0</ref>
      <ref url="http://secunia.com/advisories/23702" source="SECUNIA" patch="1" adv="1">23702</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0125" source="VUPEN">ADV-2007-0125</ref>
      <ref url="http://osvdb.org/32666" source="OSVDB">32666</ref>
      <ref url="http://www.securityfocus.com/bid/21987" source="BID">21987</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:199" source="MANDRIVA">MDKSA-2007:199</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers prev="1" num="2.9.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0204" published="2007-01-11" name="CVE-2007-0204" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.9.2-rc1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23702" source="SECUNIA" patch="1" adv="1">23702</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0125" source="VUPEN">ADV-2007-0125</ref>
      <ref url="http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0" source="MISC" adv="1">http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0</ref>
      <ref url="http://osvdb.org/32667" source="OSVDB">32667</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31387" source="XF">phpmyadmin-unspecified-xss(31387)</ref>
      <ref url="http://www.securityfocus.com/bid/21987" source="BID">21987</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:199" source="MANDRIVA">MDKSA-2007:199</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers prev="1" num="2.9.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0205" published="2007-01-11" name="CVE-2007-0205" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in admin/skins.php for @lex Guestbook 4.0.2 and earlier allows remote attackers to create files in arbitrary directories via ".." sequences in the (1) aj_skin and (2) skin_edit parameters.  NOTE: this can be leveraged for file inclusion by creating a skin file in the lang directory, then referencing that file via the lang parameter to index.php, which passes a sanity check in livre_include.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31397" source="XF">@lexguestbook-livreinclude-file-include(31397)</ref>
      <ref url="http://www.securityfocus.com/bid/21926" source="BID">21926</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456218/100/0/threaded" source="BUGTRAQ">20070107 @lex Guestbook &lt;= 4.0.2 Remote Command Execution Exploit</ref>
      <ref url="http://securityreason.com/securityalert/2135" source="SREASON">2135</ref>
      <ref url="http://osvdb.org/31709" source="OSVDB">31709</ref>
      <ref url="http://osvdb.org/31708" source="OSVDB">31708</ref>
      <ref url="http://milw0rm.com/exploits/3103" source="MILW0RM">3103</ref>
      <ref url="http://acid-root.new.fr/poc/20070107.txt" source="MISC">http://acid-root.new.fr/poc/20070107.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alexphpteam" name="alex_guestbook">
        <vers num="3.12"/>
        <vers num="3.13"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0206" published="2007-01-11" name="CVE-2007-0206" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, and 7.50 allows remote attackers to read arbitrary files via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0153" source="VUPEN">ADV-2007-0153</ref>
      <ref url="http://www.securityfocus.com/bid/22009" source="BID">22009</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456615/100/0/threaded" source="HP">SSRT061174</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456615/100/0/threaded" source="HP">HPSBMA02175</ref>
      <ref url="http://osvdb.org/32729" source="OSVDB">32729</ref>
      <ref url="http://securitytracker.com/id?1017503" source="SECTRACK">1017503</ref>
      <ref url="http://securityreason.com/securityalert/2140" source="SREASON">2140</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="6.2" edition=""/>
        <vers num="6.2" edition=":hp_ux_10.x"/>
        <vers num="6.2" edition=":hp_ux_11.x"/>
        <vers num="6.2" edition=":solaris"/>
        <vers num="6.2" edition=":nt_4.x_windows_2000"/>
        <vers num="6.4" edition=""/>
        <vers num="6.4" edition=":hp_ux_11.x"/>
        <vers num="6.4" edition=":nt_4.x_windows_2000"/>
        <vers num="6.4" edition=":solaris"/>
        <vers num="6.41" edition=""/>
        <vers num="6.41" edition=":solaris"/>
        <vers num="7.0.1" edition=""/>
        <vers num="7.0.1" edition=":windows_2000_xp"/>
        <vers num="7.0.1" edition=":solaris"/>
        <vers num="7.0.1" edition=":hp_ux_11.x"/>
        <vers num="7.0.1" edition=":linux"/>
        <vers num="7.50" edition=""/>
        <vers num="7.50" edition=":linux"/>
        <vers num="7.50" edition=":windows_2000_xp"/>
        <vers num="7.50" edition=":solaris"/>
        <vers num="7.50" edition=":hp_ux_11.x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0208" published="2007-02-13" name="CVE-2007-0208" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac does not correctly check the properties of certain documents and warn the user of macro content, which allows user-assisted remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" source="CERT">TA07-044A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-014.mspx" source="MS" patch="1" adv="1">MS07-014</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0583" source="VUPEN" adv="1">ADV-2007-0583</ref>
      <ref url="http://www.securitytracker.com/id?1017639" source="SECTRACK">1017639</ref>
      <ref url="http://www.securityfocus.com/bid/22477" source="BID">22477</ref>
      <ref url="http://www.osvdb.org/34385" source="OSVDB">34385</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:700" source="OVAL" sig="1">oval:org.mitre.oval:def:700</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp2"/>
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
        <vers num="xp" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="word">
        <vers num="2000"/>
        <vers num="2002"/>
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="word_viewer">
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2004"/>
        <vers num="2005"/>
        <vers num="2006"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0209" published="2007-02-13" name="CVE-2007-0209" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a Word file with a malformed drawing object, which leads to memory corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" source="CERT">TA07-044A</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0583" source="VUPEN" adv="1">ADV-2007-0583</ref>
      <ref url="http://www.securitytracker.com/id?1017639" source="SECTRACK">1017639</ref>
      <ref url="http://www.securityfocus.com/bid/22482" source="BID">22482</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-014.mspx" source="MS">MS07-014</ref>
      <ref url="http://osvdb.org/34386" source="OSVDB">34386</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:187" source="OVAL" sig="1">oval:org.mitre.oval:def:187</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp2"/>
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
        <vers num="xp" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2004"/>
        <vers num="2005"/>
        <vers num="2006"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0210" published="2007-02-13" name="CVE-2007-0210" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Window Image Acquisition (WIA) Service in Microsoft Windows XP SP2 allows local users to gain privileges via unspecified vectors involving an "unchecked buffer," probably a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" source="CERT">TA07-044A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-007.mspx" source="MS" patch="1">MS07-007</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0576" source="VUPEN">ADV-2007-0576</ref>
      <ref url="http://www.securitytracker.com/id?1017634" source="SECTRACK">1017634</ref>
      <ref url="http://www.securityfocus.com/bid/22499" source="BID">22499</ref>
      <ref url="http://www.osvdb.org/31889" source="OSVDB">31889</ref>
      <ref url="http://secunia.com/advisories/24132" source="SECUNIA">24132</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:186" source="OVAL" sig="1">oval:org.mitre.oval:def:186</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:tablet_pc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0211" published="2007-02-13" name="CVE-2007-0211" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The hardware detection functionality in the Windows Shell in Microsoft Windows XP SP2 and Professional, and Server 2003 SP1 allows local users to gain privileges via an unvalidated parameter to a function related to the "detection and registration of new hardware."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" source="CERT">TA07-044A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/240796" source="CERT-VN">VU#240796</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-006.mspx" source="MS" patch="1">MS07-006</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0575" source="VUPEN">ADV-2007-0575</ref>
      <ref url="http://www.securitytracker.com/id?1017633" source="SECTRACK">1017633</ref>
      <ref url="http://www.securityfocus.com/bid/22481" source="BID">22481</ref>
      <ref url="http://www.osvdb.org/31890" source="OSVDB">31890</ref>
      <ref url="http://secunia.com/advisories/24126" source="SECUNIA">24126</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:224" source="OVAL" sig="1">oval:org.mitre.oval:def:224</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="sp1"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:tablet_pc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0213" published="2007-05-08" name="CVE-2007-0213" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME encoded e-mails, which allows remote attackers to execute arbitrary code via a crafted base64-encoded MIME e-mail message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" source="CERT">TA07-128A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/343145" source="CERT-VN">VU#343145</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-026.mspx" source="MS" patch="1">MS07-026</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1711" source="VUPEN">ADV-2007-1711</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33889" source="XF">exchange-mime-base64-code-execution(33889)</ref>
      <ref url="http://www.securitytracker.com/id?1018015" source="SECTRACK">1018015</ref>
      <ref url="http://www.securityfocus.com/bid/23809" source="BID">23809</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">HPSBST02214</ref>
      <ref url="http://www.osvdb.org/34391" source="OSVDB">34391</ref>
      <ref url="http://secunia.com/advisories/25183" source="SECUNIA">25183</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1890" source="OVAL" sig="1">oval:org.mitre.oval:def:1890</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp1"/>
        <vers num="2003" edition="sp2"/>
        <vers num="2007"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0214" published="2007-02-13" name="CVE-2007-0214" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The HTML Help ActiveX control (Hhctrl.ocx) in Microsoft Windows 2000 SP3, XP SP2 and Professional, 2003 SP1 allows remote attackers to execute arbitrary code via unspecified functions, related to uninitialized parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/563756" source="CERT-VN">VU#563756</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" source="CERT">TA07-044A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-008.mspx" source="MS" patch="1">MS07-008</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0577" source="VUPEN">ADV-2007-0577</ref>
      <ref url="http://www.securitytracker.com/id?1017635" source="SECTRACK">1017635</ref>
      <ref url="http://www.securityfocus.com/bid/22478" source="BID">22478</ref>
      <ref url="http://www.osvdb.org/31884" source="OSVDB">31884</ref>
      <ref url="http://secunia.com/advisories/24136" source="SECUNIA">24136</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:125" source="OVAL" sig="1">oval:org.mitre.oval:def:125</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="64-bit"/>
        <vers num="itanium"/>
        <vers num="sp1" edition=""/>
        <vers num="sp1" edition=":itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":64-bit"/>
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0215" published="2007-05-08" name="CVE-2007-0215" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a .XLS BIFF file with a malformed Named Graph record, which results in memory corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" source="CERT">TA07-128A</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-026.html" source="MISC" patch="1">http://www.zerodayinitiative.com/advisories/ZDI-07-026.html</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-023.mspx" source="MS" patch="1">MS07-023</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1708" source="VUPEN">ADV-2007-1708</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33913" source="XF">excel-biff-file-bo(33913)</ref>
      <ref url="http://www.securitytracker.com/id?1018012" source="SECTRACK">1018012</ref>
      <ref url="http://www.securityfocus.com/bid/23760" source="BID">23760</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/467988/100/0/threaded" source="BUGTRAQ">20070508 ZDI-07-026: Microsoft Excel BIFF File Format Named Graph Record Parsing Stack Overflow Vulnerability</ref>
      <ref url="http://www.osvdb.org/34393" source="OSVDB">34393</ref>
      <ref url="http://secunia.com/advisories/25150" source="SECUNIA">25150</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1971" source="OVAL" sig="1">oval:org.mitre.oval:def:1971</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000"/>
        <vers num="2002"/>
        <vers num="2003"/>
        <vers num="2007"/>
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp2"/>
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
        <vers num="2007"/>
        <vers num="xp" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0216" published="2008-02-12" name="CVE-2007-0216" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section length headers, aka "Microsoft Works File Converter Input Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" source="CERT">TA08-043C</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-011.mspx" source="MS" patch="1">MS08-011</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0513/references" source="VUPEN" adv="1">ADV-2008-0513</ref>
      <ref url="http://www.securitytracker.com/id?1019386" source="SECTRACK">1019386</ref>
      <ref url="http://www.securityfocus.com/bid/27657" source="BID">27657</ref>
      <ref url="http://secunia.com/advisories/28904" source="SECUNIA" adv="1">28904</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">SSRT080016</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">HPSBST02314</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=659" source="IDEFENSE">20080208 Microsoft Office Works Converter Heap Overflow Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5309" source="OVAL" sig="1">oval:org.mitre.oval:def:5309</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2003" edition="sp2"/>
        <vers num="2003" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2005"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0217" published="2007-02-13" name="CVE-2007-0217" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitrary code via an FTP server response of a specific length that causes a terminating null byte to be written outside of a buffer, which causes heap corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/613564" source="CERT-VN">VU#613564</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" source="CERT">TA07-044A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-016.mspx" source="MS" patch="1">MS07-016</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0584" source="VUPEN">ADV-2007-0584</ref>
      <ref url="http://www.securitytracker.com/id?1017642" source="SECTRACK">1017642</ref>
      <ref url="http://www.securityfocus.com/bid/22489" source="BID">22489</ref>
      <ref url="http://www.osvdb.org/31892" source="OSVDB">31892</ref>
      <ref url="http://secunia.com/advisories/24156" source="SECUNIA">24156</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=473" source="IDEFENSE">20070213 Microsoft 'wininet.dll' FTP Reply Null Termination Heap Corruption Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462303/100/0/threaded" source="BUGTRAQ">20070309 MS07-016 FTP Response DOS PoC</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1141" source="OVAL" sig="1">oval:org.mitre.oval:def:1141</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp4"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0218" published="2007-06-12" name="CVE-2007-0218" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.01 and 6 allows remote attackers to execute arbitrary code by instantiating certain COM objects from Urlmon.dll, which triggers memory corruption during a call to the IObjectSafety function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-163A.html" source="CERT">TA07-163A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-033.mspx" source="MS" patch="1" adv="1">MS07-033</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32106" source="XF">webbrowser-object-code-execution(32106)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2153" source="VUPEN" adv="1">ADV-2007-2153</ref>
      <ref url="http://www.securityfocus.com/bid/24372" source="BID">24372</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded" source="HP">HPSBST02231</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded" source="HP">HPSBST02231</ref>
      <ref url="http://securitytracker.com/id?1018235" source="SECTRACK">1018235</ref>
      <ref url="http://secunia.com/advisories/25627" source="SECUNIA" adv="1">25627</ref>
      <ref url="http://osvdb.org/35348" source="OSVDB">35348</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=542" source="IDEFENSE">20070612 Microsoft License Manager and urlmon.dll COM Object Interaction Invalid Memory Access Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1084" source="OVAL" sig="1">oval:org.mitre.oval:def:1084</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp4"/>
        <vers num="6" edition="sp1"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0219" published="2007-02-13" name="CVE-2007-0219" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from (1) Msb1fren.dll, (2) Htmlmm.ocx, and (3) Blnmgrps.dll as ActiveX controls, which allows remote attackers to execute arbitrary code via unspecified vectors, a different issue than CVE-2006-4697.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/771788" source="CERT-VN">VU#771788</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" source="CERT">TA07-044A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-016.mspx" source="MS" patch="1">MS07-016</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32427" source="XF">ie-com-activex-code-execution(32427)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0584" source="VUPEN">ADV-2007-0584</ref>
      <ref url="http://www.securitytracker.com/id?1017643" source="SECTRACK">1017643</ref>
      <ref url="http://www.securityfocus.com/bid/22504" source="BID">22504</ref>
      <ref url="http://www.osvdb.org/31895" source="OSVDB">31895</ref>
      <ref url="http://www.osvdb.org/31894" source="OSVDB">31894</ref>
      <ref url="http://www.osvdb.org/31893" source="OSVDB">31893</ref>
      <ref url="http://secunia.com/advisories/24156" source="SECUNIA">24156</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:257" source="OVAL" sig="1">oval:org.mitre.oval:def:257</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp4"/>
        <vers num="6.0" edition="sp1"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0220" published="2007-05-08" name="CVE-2007-0220" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 allows remote attackers to execute arbitrary scripts, spoof content, or obtain sensitive information via certain UTF-encoded, script-based e-mail attachments, involving an "incorrectly handled UTF character set label".</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" source="CERT">TA07-128A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/124113" source="CERT-VN">VU#124113</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-026.mspx" source="MS" patch="1">MS07-026</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1711" source="VUPEN">ADV-2007-1711</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33887" source="XF">exchange-utf-xss(33887)</ref>
      <ref url="http://www.securitytracker.com/id?1018015" source="SECTRACK">1018015</ref>
      <ref url="http://www.securityfocus.com/bid/23806" source="BID">23806</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">HPSBST02214</ref>
      <ref url="http://www.osvdb.org/34389" source="OSVDB">34389</ref>
      <ref url="http://secunia.com/advisories/25183" source="SECUNIA">25183</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1371" source="OVAL" sig="1">oval:org.mitre.oval:def:1371</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp1"/>
        <vers num="2003" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0221" published="2007-05-08" name="CVE-2007-0221" modified="2011-10-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Integer overflow in the IMAP (IMAP4) support in Microsoft Exchange Server 2000 SP3 allows remote attackers to cause a denial of service (service hang) via crafted literals in an IMAP command, aka the "IMAP Literal Processing Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" source="CERT">TA07-128A</ref>
      <ref url="http://www.securitytracker.com/id?1018015" source="SECTRACK" patch="1">1018015</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-026.mspx" source="MS" patch="1">MS07-026</ref>
      <ref url="http://secunia.com/advisories/25183" source="SECUNIA" patch="1" adv="1">25183</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=526" source="IDEFENSE" patch="1">20070508 Microsoft Exchange Server 2000 IMAP Literal Processing DoS Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33890" source="XF">exchange-imap-command-dos(33890)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1711" source="VUPEN" adv="1">ADV-2007-1711</ref>
      <ref url="http://www.securityfocus.com/bid/23810" source="BID">23810</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">HPSBST02214</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://www.osvdb.org/34392" source="OSVDB">34392</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2054" source="OVAL" sig="1">oval:org.mitre.oval:def:2054</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0222" published="2007-01-16" name="CVE-2007-0222" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the EmChartBean server side component for Oracle Application Server 10g allows remote attackers to read arbitrary files via unknown vectors, probably "\.." sequences in the beanId parameter.  NOTE: this is likely a duplicate of another CVE that Oracle addressed in CPU Jan 2007, but due to lack of details by Oracle, it is unclear which BugID this issue is associated with, so the other CVE cannot be determined.  Possibilities include EM02 (CVE-2007-0292) or EM05 (CVE-2007-0293).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22027" source="BID" patch="1">22027</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457105/100/0/threaded" source="BUGTRAQ" patch="1">20070115 SYMSA-2007-001: Oracle Application Server 10g - Directory Traversal</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458657/100/0/threaded" source="BUGTRAQ">20070131 Oracle 10g R2 Enterprise Manager Directory Traversal</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0223" published="2007-01-12" name="CVE-2007-0223" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in shared/code/cp_functions_downloads.php in Nicola Asuni All In One Control Panel (AIOCP) before 1.3.009 allows remote attackers to execute arbitrary SQL commands via the download_category parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=477845" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=477845</ref>
      <ref url="http://secunia.com/advisories/23726" source="SECUNIA" patch="1" adv="1">23726</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31591" source="XF">aiocp-cpfunctionsdownloads-sql-injection(31591)</ref>
      <ref url="http://www.securityfocus.com/bid/22019" source="BID">22019</ref>
      <ref url="http://osvdb.org/31641" source="OSVDB">31641</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nicola_asuni" name="all_in_one_control_panel">
        <vers num="1.3.000"/>
        <vers num="1.3.001"/>
        <vers num="1.3.002"/>
        <vers num="1.3.003"/>
        <vers num="1.3.004"/>
        <vers num="1.3.005"/>
        <vers num="1.3.006"/>
        <vers num="1.3.007"/>
        <vers num="1.3.008"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0224" published="2007-01-12" name="CVE-2007-0224" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in shopgiftregsearch.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to execute arbitrary SQL commands via the LoginLastname parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23699" source="SECUNIA" adv="1">23699</ref>
      <ref url="http://osvdb.org/32732" source="OSVDB">32732</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31447" source="XF">vpasp-shopgift-sql-injection(31447)</ref>
      <ref url="http://milw0rm.com/exploits/3115" source="MILW0RM">3115</ref>
    </refs>
    <vuln_soft>
      <prod vendor="virtual_programming" name="vp-asp">
        <vers num="6.09"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0225" published="2007-01-12" name="CVE-2007-0225" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in shopcustadmin.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23699" source="SECUNIA" adv="1">23699</ref>
      <ref url="http://osvdb.org/32733" source="OSVDB">32733</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31449" source="XF">vpasp-shopcustadmin-xss(31449)</ref>
      <ref url="http://milw0rm.com/exploits/3115" source="MILW0RM">3115</ref>
    </refs>
    <vuln_soft>
      <prod vendor="virtual_programming" name="vp-asp">
        <vers num="6.09"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0226" published="2007-01-12" name="CVE-2007-0226" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in wbsearch.aspx in uniForum 4 and earlier allows remote attackers to execute arbitrary SQL commands via the "by User" field (aka the TXbyuser parameter).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31362" source="XF">uniforum-wbsearch-sql-injection(31362)</ref>
      <ref url="http://www.securityfocus.com/bid/21966" source="BID">21966</ref>
      <ref url="http://osvdb.org/32927" source="OSVDB">32927</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458060/100/0/threaded" source="BUGTRAQ">20070125 uniForum &lt;= v4 (wbsearch.aspx) Remote SQL Injection Vulnerability</ref>
      <ref url="http://secunia.com/advisories/23827" source="SECUNIA">23827</ref>
      <ref url="http://milw0rm.com/exploits/3106" source="MILW0RM">3106</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uniforum" name="uniforum">
        <vers prev="1" num="4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0227" published="2007-01-12" name="CVE-2007-0227" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">slocate 3.1 does not properly manage database entries that specify names of files in protected directories, which allows local users to obtain the names of private files.  NOTE: another researcher reports that the issue is not present in slocate 2.7.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21989" source="BID">21989</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464220/30/7320/threaded" source="BUGTRAQ">20070329 FLEA-2007-0005-1: slocate</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456530/100/0/threaded" source="BUGTRAQ">20070110 Re: slocate leaks filenames of protected directories</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456489/100/0/threaded" source="BUGTRAQ">20070110 slocate leaks filenames of protected directories</ref>
      <ref url="http://www.securityfocus.com/archive/1/456593/100/0/threaded" source="BUGTRAQ">20070111 Re: slocate leaks filenames of protected directories</ref>
      <ref url="http://osvdb.org/33465" source="OSVDB">33465</ref>
      <ref url="http://www.ubuntu.com/usn/usn-425-1" source="UBUNTU">USN-425-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456739/100/0/threaded" source="BUGTRAQ">20070112 Re: slocate leaks filenames of protected directories</ref>
    </refs>
    <vuln_soft>
      <prod vendor="slocate" name="slocate">
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0228" published="2007-01-12" name="CVE-2007-0228" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DataCollector service in EIQ Networks Network Security Analyzer allows remote attackers to cause a denial of service (service crash) via a (1) &amp;CONNECTSERVER&amp; (2) &amp;ADDENTRY&amp; (3) &amp;FIN&amp; (4) &amp;START&amp; (5) &amp;LOGPATH&amp; (6) &amp;FWADELTA&amp; (7) &amp;FWALOG&amp; (8) &amp;SETSYNCHRONOUS&amp; (9) &amp;SETPRGFILE&amp;, or (10) &amp;SETREPLYPORT&amp; string to TCP port 10618, which triggers a NULL pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0147" source="VUPEN">ADV-2007-0147</ref>
      <ref url="http://www.securityfocus.com/bid/21994" source="BID">21994</ref>
      <ref url="http://osvdb.org/32725" source="OSVDB">32725</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0209.html" source="FULLDISC">20070110 EIQ Networks Network Security Analyzer DoS Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31428" source="XF">eiq-datacollector-dos(31428)</ref>
      <ref url="http://secunia.com/advisories/23693" source="SECUNIA">23693</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eiqnetworks" name="enterprise_security_analyzer">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0229" published="2007-01-12" name="CVE-2007-0229" modified="2011-10-11" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly gain privileges via a crafted DMG image that causes "allocation of a negative size buffer" leading to a heap-based buffer overflow, a related issue to CVE-2006-5679.  NOTE: a third party states that this issue does not cross privilege boundaries in FreeBSD because only root may mount a filesystem.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31409" source="XF">macos-ffsmountfs-bo(31409)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN" adv="1">ADV-2007-0930</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0141" source="VUPEN" adv="1">ADV-2007-0141</ref>
      <ref url="http://www.securitytracker.com/id?1017751" source="SECTRACK">1017751</ref>
      <ref url="http://www.securityfocus.com/bid/21993" source="BID">21993</ref>
      <ref url="http://www.osvdb.org/32684" source="OSVDB">32684</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://secunia.com/advisories/23703" source="SECUNIA" adv="1">23703</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-10-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-10-01-2007.html</ref>
      <ref url="http://lists.freebsd.org/pipermail/freebsd-security/2007-January/004218.html" source="MLIST">[freebsd-security] 20070114 MOAB advisories</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE">APPLE-SA-2007-03-13</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
      <ref url="http://applefun.blogspot.com/2007/01/moab-10-01-2007-apple-dmg-ufs.html" source="MISC">http://applefun.blogspot.com/2007/01/moab-10-01-2007-apple-dmg-ufs.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.8"/>
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0230" reject="1" published="2007-01-12" name="CVE-2007-0230" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED ** PHP remote file inclusion vulnerability in install.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in the install_dir parameter.  NOTE: CVE and third parties dispute this vulnerability because install_dir is defined before use.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31408" source="XF">cscart-install-file-include(31408)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456527/100/0/threaded" source="BUGTRAQ">20070109 CS-Cart 1.3.3 (install.php) Remote File Include Vulnerability</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001223.html" source="VIM">20070110 [bogus] [ahmed_labib_hilmy at yahoo.com: CS-Cart 1.3.3 (install.php) Remote File Include Vulnerability] (fwd)</ref>
      <ref url="http://osvdb.org/31277" source="OSVDB">31277</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cs-cart" name="cs-cart">
        <vers num="1.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0231" published="2007-01-12" name="CVE-2007-0231" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Movable Type (MT) 3.33, when nofollow is disabled and unmoderated comments are enabled, allows remote attackers to inject arbitrary web script or HTML via the Comments field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.zackvision.com/weblog/2007/01/movabletype-security-bug.html" source="MISC" adv="1">http://www.zackvision.com/weblog/2007/01/movabletype-security-bug.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0142" source="VUPEN">ADV-2007-0142</ref>
      <ref url="http://secunia.com/advisories/23669" source="SECUNIA">23669</ref>
      <ref url="http://osvdb.org/32717" source="OSVDB">32717</ref>
      <ref url="http://golem.ph.utexas.edu/~distler/blog/archives/001102.html" source="MISC" adv="1">http://golem.ph.utexas.edu/~distler/blog/archives/001102.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="six_apart" name="movable_type">
        <vers num="3.33"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0232" published="2007-01-12" name="CVE-2007-0232" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in routines/fieldValidation.php in Jshop Server 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the jssShopFileSystem parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21995" source="BID">21995</ref>
      <ref url="http://osvdb.org/33459" source="OSVDB">33459</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31425" source="XF">jshop-fieldvalidation-file-include(31425)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456591/100/0/threaded" source="BUGTRAQ">20070110 Jshop Server 1.3</ref>
      <ref url="http://securityreason.com/securityalert/2146" source="SREASON">2146</ref>
      <ref url="http://milw0rm.com/exploits/3113" source="MILW0RM">3113</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jshop_e-commerce" name="jshop_server">
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0233" published="2007-01-12" name="CVE-2007-0233" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL commands via the tb_id parameter.  NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in WordPress.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21983" source="BID">21983</ref>
      <ref url="http://osvdb.org/36860" source="OSVDB">36860</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31385" source="XF">wordpress-tbid-sql-injection(31385)</ref>
      <ref url="http://milw0rm.com/exploits/3109" source="MILW0RM">3109</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="0.6.2" edition="beta_2"/>
        <vers num="0.6.2.1" edition="beta_2"/>
        <vers num="0.7"/>
        <vers num="0.71"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.5"/>
        <vers num="1.5.1"/>
        <vers num="1.5.1.2"/>
        <vers num="1.5.1.3"/>
        <vers num="1.5.2"/>
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2007-0234" reject="1" published="2007-01-16" name="CVE-2007-0234" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-0243.  Reason: This candidate is a duplicate of CVE-2007-0243.  Notes: All CVE users should reference CVE-2007-0243 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <refs/>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0235" published="2007-01-16" name="CVE-2007-0235" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the glibtop_get_proc_map_s function in libgtop before 2.14.6 (libgtop2) allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a process with a long filename that is mapped in its address space, which triggers the overflow in gnome-system-monitor.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://launchpad.net/bugs/79206" source="MISC">https://launchpad.net/bugs/79206</ref>
      <ref url="https://issues.rpath.com/browse/RPL-972" source="CONFIRM">https://issues.rpath.com/browse/RPL-972</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31522" source="XF">libgtop2-glibtopbo(31522)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0187" source="VUPEN">ADV-2007-0187</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0185" source="VUPEN">ADV-2007-0185</ref>
      <ref url="http://www.ubuntu.com/usn/usn-407-1" source="UBUNTU">USN-407-1</ref>
      <ref url="http://www.securityfocus.com/bid/22054" source="BID">22054</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:023" source="MANDRIVA">MDKSA-2007:023</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1255" source="DEBIAN">DSA-1255</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200701-17.xml" source="GENTOO">GLSA-200701-17</ref>
      <ref url="http://secunia.com/advisories/24015" source="SECUNIA" adv="1">24015</ref>
      <ref url="http://secunia.com/advisories/23872" source="SECUNIA" adv="1">23872</ref>
      <ref url="http://secunia.com/advisories/23840" source="SECUNIA" adv="1">23840</ref>
      <ref url="http://secunia.com/advisories/23814" source="SECUNIA" adv="1">23814</ref>
      <ref url="http://secunia.com/advisories/23777" source="SECUNIA" adv="1">23777</ref>
      <ref url="http://secunia.com/advisories/23736" source="SECUNIA" adv="1">23736</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10720" source="OVAL">oval:org.mitre.oval:def:10720</ref>
      <ref url="http://osvdb.org/32815" source="OSVDB">32815</ref>
      <ref url="http://ftp.gnome.org/pub/gnome/sources/libgtop/2.14/libgtop-2.14.6.news" source="CONFIRM">http://ftp.gnome.org/pub/gnome/sources/libgtop/2.14/libgtop-2.14.6.news</ref>
      <ref url="http://bugzilla.gnome.org/show_bug.cgi?id=396477" source="CONFIRM">http://bugzilla.gnome.org/show_bug.cgi?id=396477</ref>
      <ref url="http://www.securitytracker.com/id?1018526" source="SECTRACK">1018526</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0765.html" source="REDHAT">RHSA-2007:0765</ref>
      <ref url="http://secunia.com/advisories/26367" source="SECUNIA">26367</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libgtop" name="libgtop">
        <vers prev="1" num="2.14.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0236" published="2007-01-16" name="CVE-2007-0236" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Double free vulnerability in the _ATPsndrsp function in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (kernel panic) and possibly execute arbitrary code via a crafted AppleTalk request that triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0191" source="VUPEN">ADV-2007-0191</ref>
      <ref url="http://www.securitytracker.com/id?1017751" source="SECTRACK">1017751</ref>
      <ref url="http://www.securityfocus.com/bid/22041" source="BID">22041</ref>
      <ref url="http://www.osvdb.org/32687" source="OSVDB">32687</ref>
      <ref url="http://www.milw0rm.com/exploits/3130" source="MILW0RM">3130</ref>
      <ref url="http://securitytracker.com/id?1017513" source="SECTRACK">1017513</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA" adv="1">24479</ref>
      <ref url="http://secunia.com/advisories/23708" source="SECUNIA" adv="1">23708</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-14-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-14-01-2007.html</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE">APPLE-SA-2007-03-13</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0237" published="2007-03-19" name="CVE-2007-0237" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The ndeb-binary feature in Lookup (lookup-el) allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2007/dsa-1269" source="DEBIAN" patch="1" adv="1">DSA-1269</ref>
      <ref url="http://secunia.com/advisories/24590" source="SECUNIA" patch="1" adv="1">24590</ref>
      <ref url="http://secunia.com/advisories/24377" source="SECUNIA" adv="1">24377</ref>
      <ref url="http://osvdb.org/34263" source="OSVDB">34263</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33052" source="XF">lookup-ndebbinary-symlink(33052)</ref>
      <ref url="http://www.securitytracker.com/id?1017792" source="SECTRACK">1017792</ref>
      <ref url="http://www.securityfocus.com/bid/23026" source="BID">23026</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200712-07.xml" source="GENTOO">GLSA-200712-07</ref>
      <ref url="http://secunia.com/advisories/28023" source="SECUNIA">28023</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=197306" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=197306</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lookup" name="lookup">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0238" published="2007-03-21" name="CVE-2007-0238" modified="2011-07-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in filter\starcalc\scflt.cxx in the StarCalc parser in OpenOffice.org (OOo) Office Suite before 2.2, and 1.x before 1.1.5 Patch, allows user-assisted remote attackers to execute arbitrary code via a document with a long Note.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://issues.rpath.com/browse/RPL-1118" source="CONFIRM">https://issues.rpath.com/browse/RPL-1118</ref>
      <ref url="https://issues.foresightlinux.org/browse/FL-211" source="CONFIRM">https://issues.foresightlinux.org/browse/FL-211</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33112" source="XF">openoffice-starcalc-bo(33112)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1117" source="VUPEN" adv="1">ADV-2007-1117</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1032" source="VUPEN" adv="1">ADV-2007-1032</ref>
      <ref url="http://www.ubuntu.com/usn/usn-444-1" source="UBUNTU">USN-444-1</ref>
      <ref url="http://www.securitytracker.com/id?1017799" source="SECTRACK">1017799</ref>
      <ref url="http://www.securityfocus.com/bid/23067" source="BID">23067</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464724/100/0/threaded" source="BUGTRAQ">20070404 High Risk Vulnerability in OpenOffice</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0069.html" source="REDHAT">RHSA-2007:0069</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0033.html" source="REDHAT">RHSA-2007:0033</ref>
      <ref url="http://www.openoffice.org/security/CVE-2007-0238" source="CONFIRM">http://www.openoffice.org/security/CVE-2007-0238</ref>
      <ref url="http://www.ngssoftware.com/advisories/high-risk-vulnerabilities-in-the-openoffice-suite/" source="MISC">http://www.ngssoftware.com/advisories/high-risk-vulnerabilities-in-the-openoffice-suite/</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:073" source="MANDRIVA">MDKSA-2007:073</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200704-12.xml" source="GENTOO">GLSA-200704-12</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1270" source="DEBIAN" adv="1">DSA-1270</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102794-1" source="SUNALERT">102794</ref>
      <ref url="http://secunia.com/advisories/24906" source="SECUNIA" adv="1">24906</ref>
      <ref url="http://secunia.com/advisories/24810" source="SECUNIA" adv="1">24810</ref>
      <ref url="http://secunia.com/advisories/24676" source="SECUNIA" adv="1">24676</ref>
      <ref url="http://secunia.com/advisories/24647" source="SECUNIA" adv="1">24647</ref>
      <ref url="http://secunia.com/advisories/24646" source="SECUNIA" adv="1">24646</ref>
      <ref url="http://secunia.com/advisories/24613" source="SECUNIA" adv="1">24613</ref>
      <ref url="http://secunia.com/advisories/24588" source="SECUNIA" adv="1">24588</ref>
      <ref url="http://secunia.com/advisories/24550" source="SECUNIA" adv="1">24550</ref>
      <ref url="http://secunia.com/advisories/24465" source="SECUNIA" adv="1">24465</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8968" source="OVAL">oval:org.mitre.oval:def:8968</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0007.html" source="SUSE">SUSE-SA:2007:023</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openoffice" name="openoffice">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0239" published="2007-03-21" name="CVE-2007-0239" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">OpenOffice.org (OOo) Office Suite allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a prepared link in a crafted document.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1117" source="VUPEN">ADV-2007-1117</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1032" source="VUPEN">ADV-2007-1032</ref>
      <ref url="http://www.securitytracker.com/id?1017799" source="SECTRACK">1017799</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1270" source="DEBIAN" adv="1">DSA-1270</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11422" source="OVAL">oval:org.mitre.oval:def:11422</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1118" source="CONFIRM">https://issues.rpath.com/browse/RPL-1118</ref>
      <ref url="https://issues.foresightlinux.org/browse/FL-211" source="CONFIRM">https://issues.foresightlinux.org/browse/FL-211</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33113" source="XF">openoffice-shell-command-execution(33113)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-444-1" source="UBUNTU">USN-444-1</ref>
      <ref url="http://www.securityfocus.com/bid/22812" source="BID">22812</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0069.html" source="REDHAT">RHSA-2007:0069</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0033.html" source="REDHAT">RHSA-2007:0033</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:073" source="MANDRIVA">MDKSA-2007:073</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200704-12.xml" source="GENTOO">GLSA-200704-12</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102807-1" source="SUNALERT">102807</ref>
      <ref url="http://secunia.com/advisories/24906" source="SECUNIA">24906</ref>
      <ref url="http://secunia.com/advisories/24810" source="SECUNIA">24810</ref>
      <ref url="http://secunia.com/advisories/24676" source="SECUNIA">24676</ref>
      <ref url="http://secunia.com/advisories/24647" source="SECUNIA">24647</ref>
      <ref url="http://secunia.com/advisories/24646" source="SECUNIA">24646</ref>
      <ref url="http://secunia.com/advisories/24613" source="SECUNIA">24613</ref>
      <ref url="http://secunia.com/advisories/24588" source="SECUNIA">24588</ref>
      <ref url="http://secunia.com/advisories/24550" source="SECUNIA">24550</ref>
      <ref url="http://secunia.com/advisories/24465" source="SECUNIA">24465</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0007.html" source="SUSE">SUSE-SA:2007:023</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openoffice" name="openoffice">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0240" published="2007-03-22" name="CVE-2007-0240" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Zope 2.10.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a HTTP GET request.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.zope.org/Products/Zope/Hotfix-2007-03-20/announcement/view" source="CONFIRM" patch="1" adv="1">http://www.zope.org/Products/Zope/Hotfix-2007-03-20/announcement/view</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1041" source="VUPEN">ADV-2007-1041</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33187" source="XF">zope-unspecifiedget-xss(33187)</ref>
      <ref url="http://www.securityfocus.com/bid/23084" source="BID">23084</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1275" source="DEBIAN">DSA-1275</ref>
      <ref url="http://secunia.com/advisories/25239" source="SECUNIA">25239</ref>
      <ref url="http://secunia.com/advisories/24713" source="SECUNIA">24713</ref>
      <ref url="http://secunia.com/advisories/24017" source="SECUNIA">24017</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-May/0005.html" source="SUSE">SUSE-SR:2007:011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zope" name="zope">
        <vers prev="1" num="2.10.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0242" published="2007-04-03" name="CVE-2007-0242" modified="2012-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The UTF-8 decoder in codecs/qutfcodec.cpp in Qt 3.3.8 and 4.2.3 does not reject long UTF-8 sequences as required by the standard, which allows remote attackers to conduct cross-site scripting (XSS) and directory traversal attacks via long sequences that decode to dangerous metacharacters.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.trolltech.com/company/newsroom/announcements/press.2007-03-30.9172215350" source="CONFIRM" patch="1">http://www.trolltech.com/company/newsroom/announcements/press.2007-03-30.9172215350</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1212" source="VUPEN">ADV-2007-1212</ref>
      <ref url="http://www.nabble.com/Bug-417390:-CVE-2007-0242,--Qt-UTF-8-overlong-sequence-decoding-vulnerability-t3506065.html" source="CONFIRM" adv="1">http://www.nabble.com/Bug-417390:-CVE-2007-0242,--Qt-UTF-8-overlong-sequence-decoding-vulnerability-t3506065.html</ref>
      <ref url="http://secunia.com/advisories/46117" source="SECUNIA">46117</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2011-1324.html" source="REDHAT">RHSA-2011:1324</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11510" source="OVAL">oval:org.mitre.oval:def:11510</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1202" source="CONFIRM">https://issues.rpath.com/browse/RPL-1202</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33397" source="XF">qt-utf8-xss(33397)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-452-1" source="UBUNTU">USN-452-1</ref>
      <ref url="http://www.securityfocus.com/bid/23269" source="BID">23269</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0909.html" source="REDHAT">RHSA-2007:0909</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0883.html" source="REDHAT">RHSA-2007:0883</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_6_sr.html" source="SUSE">SUSE-SR:2007:006</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:076" source="MANDRIVA">MDKSA-2007:076</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:075" source="MANDRIVA">MDKSA-2007:075</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:074" source="MANDRIVA">MDKSA-2007:074</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1292" source="DEBIAN">DSA-1292</ref>
      <ref url="http://support.novell.com/techcenter/psdb/fc79b7f48d739f9c803a24ddad933384.html" source="CONFIRM">http://support.novell.com/techcenter/psdb/fc79b7f48d739f9c803a24ddad933384.html</ref>
      <ref url="http://support.novell.com/techcenter/psdb/39ea4b325a7da742cb8b6995fa585b14.html" source="CONFIRM">http://support.novell.com/techcenter/psdb/39ea4b325a7da742cb8b6995fa585b14.html</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-424.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-424.htm</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.348591" source="SLACKWARE">SSA:2007-093-03</ref>
      <ref url="http://secunia.com/advisories/27275" source="SECUNIA">27275</ref>
      <ref url="http://secunia.com/advisories/27108" source="SECUNIA">27108</ref>
      <ref url="http://secunia.com/advisories/26857" source="SECUNIA">26857</ref>
      <ref url="http://secunia.com/advisories/26804" source="SECUNIA">26804</ref>
      <ref url="http://secunia.com/advisories/25263" source="SECUNIA">25263</ref>
      <ref url="http://secunia.com/advisories/24889" source="SECUNIA">24889</ref>
      <ref url="http://secunia.com/advisories/24847" source="SECUNIA">24847</ref>
      <ref url="http://secunia.com/advisories/24797" source="SECUNIA">24797</ref>
      <ref url="http://secunia.com/advisories/24759" source="SECUNIA">24759</ref>
      <ref url="http://secunia.com/advisories/24727" source="SECUNIA">24727</ref>
      <ref url="http://secunia.com/advisories/24726" source="SECUNIA">24726</ref>
      <ref url="http://secunia.com/advisories/24705" source="SECUNIA">24705</ref>
      <ref url="http://secunia.com/advisories/24699" source="SECUNIA">24699</ref>
      <ref url="http://fedoranews.org/updates/FEDORA-2007-703.shtml" source="FEDORA">FEDORA-2007-703</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070901-01-P.asc" source="SGI">20070901-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qt" name="qt">
        <vers num="3.3.8"/>
        <vers num="4.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0243" published="2007-01-17" name="CVE-2007-0243" modified="2011-03-07" discovered="2006-06-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in Sun JDK and Java Runtime Environment (JRE) 5.0 Update 9 and earlier, SDK and JRE 1.4.2_12 and earlier, and SDK and JRE 1.3.1_18 and earlier allows applets to gain privileges via a GIF image with a block with a 0 width field, which triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-022A.html" source="CERT">TA07-022A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/388289" source="CERT-VN">VU#388289</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-005.html" source="MISC" patch="1" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-07-005.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102760-1" source="SUNALERT" patch="1">102760</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31537" source="XF">jre-gif-bo(31537)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/4224" source="VUPEN">ADV-2007-4224</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1814" source="VUPEN">ADV-2007-1814</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0936" source="VUPEN">ADV-2007-0936</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0211" source="VUPEN">ADV-2007-0211</ref>
      <ref url="http://www.securityfocus.com/bid/22085" source="BID">22085</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457638/100/0/threaded" source="BUGTRAQ">20070121 Sun Microsystems Java GIF File Parsing Memory Corruption Vulnerability Prove Of Concept Exploit</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457159/100/0/threaded" source="BUGTRAQ">20070117 ZDI-07-005: Sun Microsystems Java GIF File Parsing Memory Corruption Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0956.html" source="REDHAT">RHSA-2007:0956</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0167.html" source="REDHAT">RHSA-2007:0167</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0166.html" source="REDHAT">RHSA-2007:0166</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_45_java.html" source="SUSE">SUSE-SA:2007:045</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200702-07.xml" source="GENTOO">GLSA-200702-07</ref>
      <ref url="http://support.novell.com/techcenter/psdb/d2f549cc040cd81ae4a268bb5edfe918.html" source="CONFIRM">http://support.novell.com/techcenter/psdb/d2f549cc040cd81ae4a268bb5edfe918.html</ref>
      <ref url="http://support.novell.com/techcenter/psdb/4f850d1e2b871db609de64ec70f0089c.html" source="CONFIRM">http://support.novell.com/techcenter/psdb/4f850d1e2b871db609de64ec70f0089c.html</ref>
      <ref url="http://securitytracker.com/id?1017520" source="SECTRACK">1017520</ref>
      <ref url="http://securityreason.com/securityalert/2158" source="SREASON">2158</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200702-08.xml" source="GENTOO">GLSA-200702-08</ref>
      <ref url="http://secunia.com/advisories/28115" source="SECUNIA">28115</ref>
      <ref url="http://secunia.com/advisories/27203" source="SECUNIA">27203</ref>
      <ref url="http://secunia.com/advisories/26645" source="SECUNIA">26645</ref>
      <ref url="http://secunia.com/advisories/26119" source="SECUNIA">26119</ref>
      <ref url="http://secunia.com/advisories/26049" source="SECUNIA">26049</ref>
      <ref url="http://secunia.com/advisories/25283" source="SECUNIA">25283</ref>
      <ref url="http://secunia.com/advisories/24993" source="SECUNIA">24993</ref>
      <ref url="http://secunia.com/advisories/24468" source="SECUNIA">24468</ref>
      <ref url="http://secunia.com/advisories/24202" source="SECUNIA">24202</ref>
      <ref url="http://secunia.com/advisories/24189" source="SECUNIA">24189</ref>
      <ref url="http://secunia.com/advisories/23757" source="SECUNIA">23757</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11073" source="OVAL">oval:org.mitre.oval:def:11073</ref>
      <ref url="http://osvdb.org/32834" source="OSVDB">32834</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.html" source="APPLE">APPLE-SA-2007-12-14</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579" source="HP">HPSBUX02196</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579" source="HP">HPSBUX02196</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307177" source="MISC">http://docs.info.apple.com/article.html?artnum=307177</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/242" source="BEA">BEA07-172.00</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0261.html" source="REDHAT">RHSA-2008:0261</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers prev="1" num="1.5.0" edition="update3"/>
        <vers prev="1" num="1.5.0" edition="update4"/>
        <vers prev="1" num="1.5.0" edition="update5"/>
        <vers prev="1" num="1.5.0" edition="update7"/>
        <vers prev="1" num="1.5.0" edition="update8"/>
        <vers prev="1" num="1.5.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers prev="1" num="1.3.1" edition="update16"/>
        <vers prev="1" num="1.3.1" edition="update18"/>
        <vers num="1.4.2" edition="update1"/>
        <vers num="1.4.2" edition="update10"/>
        <vers num="1.4.2" edition="update11"/>
        <vers num="1.4.2" edition="update12"/>
        <vers num="1.4.2" edition="update2"/>
        <vers num="1.4.2" edition="update3"/>
        <vers num="1.4.2" edition="update4"/>
        <vers num="1.4.2" edition="update5"/>
        <vers num="1.4.2" edition="update6"/>
        <vers num="1.4.2" edition="update7"/>
        <vers num="1.4.2" edition="update8"/>
        <vers num="1.4.2" edition="update9"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="sdk">
        <vers num="1.3.1_01"/>
        <vers num="1.3.1_01a"/>
        <vers num="1.3.1_16"/>
        <vers num="1.3.1_18"/>
        <vers num="1.4.2"/>
        <vers num="1.4.2_03"/>
        <vers num="1.4.2_08"/>
        <vers num="1.4.2_09"/>
        <vers num="1.4.2_10"/>
        <vers num="1.4.2_12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0244" published="2007-05-11" name="CVE-2007-0244" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">pptpgre.c in PoPToP Point to Point Tunneling Server (pptpd) before 1.3.4 allows remote attackers to cause a denial of service (PPTP connection tear-down) via (1) GRE packets with out-of-order sequence numbers or (2) certain GRE packets that are processed using a wrong pointer and improperly dequeued.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2007/dsa-1288" source="DEBIAN" patch="1" adv="1">DSA-1288</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1743" source="VUPEN">ADV-2007-1743</ref>
      <ref url="http://www.securityfocus.com/bid/23886" source="BID">23886</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=501476&amp;group_id=44827" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=501476&amp;group_id=44827</ref>
      <ref url="http://www.ubuntu.com/usn/usn-459-2" source="UBUNTU">USN-459-2</ref>
      <ref url="http://www.ubuntu.com/usn/usn-459-1" source="UBUNTU">USN-459-1</ref>
      <ref url="http://www.trustix.org/errata/2007/0017/" source="TRUSTIX">2007-0017</ref>
      <ref url="http://www.securitytracker.com/id?1018064" source="SECTRACK">1018064</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_19_sr.html" source="SUSE">SUSE-SR:2007:019</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_10_sr.html" source="SUSE">SUSE-SR:2007:010</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-18.xml" source="GENTOO">GLSA-200705-18</ref>
      <ref url="http://secunia.com/advisories/26987" source="SECUNIA">26987</ref>
      <ref url="http://secunia.com/advisories/25255" source="SECUNIA">25255</ref>
      <ref url="http://secunia.com/advisories/25220" source="SECUNIA">25220</ref>
    </refs>
    <vuln_soft>
      <prod vendor="poptop" name="pptp_server">
        <vers prev="1" num="1.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0245" published="2007-06-12" name="CVE-2007-0245" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in OpenOffice.org (OOo) 2.2.1 and earlier allows remote attackers to execute arbitrary code via a RTF file with a crafted prtdata tag with a length parameter inconsistency, which causes vtable entries to be overwritten.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2007/dsa-1307" source="DEBIAN" patch="1">DSA-1307</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1570" source="CONFIRM">https://issues.rpath.com/browse/RPL-1570</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34843" source="XF">openoffice-rtf-bo(34843)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2229" source="VUPEN" adv="1">ADV-2007-2229</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2166" source="VUPEN" adv="1">ADV-2007-2166</ref>
      <ref url="http://www.ubuntu.com/usn/usn-482-1" source="UBUNTU">USN-482-1</ref>
      <ref url="http://www.securitytracker.com/id?1018239" source="SECTRACK">1018239</ref>
      <ref url="http://www.securityfocus.com/bid/24450" source="BID">24450</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/471274/100/0/threaded" source="BUGTRAQ">20070613 High risk vulnerability in OpenOffice RTF parser</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0406.html" source="REDHAT">RHSA-2007:0406</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_37_openoffice.html" source="SUSE">SUSE-SA:2007:037</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:144" source="MANDRIVA">MDKSA-2007:144</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200707-02.xml" source="GENTOO">GLSA-200707-02</ref>
      <ref url="http://sw.openoffice.org/source/browse/sw/sw/source/filter/rtf/swparrtf.cxx?rev=1.67" source="CONFIRM">http://sw.openoffice.org/source/browse/sw/sw/source/filter/rtf/swparrtf.cxx?rev=1.67</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102917-1" source="SUNALERT">102917</ref>
      <ref url="http://secunia.com/advisories/26476" source="SECUNIA" adv="1">26476</ref>
      <ref url="http://secunia.com/advisories/26022" source="SECUNIA" adv="1">26022</ref>
      <ref url="http://secunia.com/advisories/26010" source="SECUNIA" adv="1">26010</ref>
      <ref url="http://secunia.com/advisories/25905" source="SECUNIA" adv="1">25905</ref>
      <ref url="http://secunia.com/advisories/25894" source="SECUNIA" adv="1">25894</ref>
      <ref url="http://secunia.com/advisories/25862" source="SECUNIA" adv="1">25862</ref>
      <ref url="http://secunia.com/advisories/25705" source="SECUNIA" adv="1">25705</ref>
      <ref url="http://secunia.com/advisories/25673" source="SECUNIA" adv="1">25673</ref>
      <ref url="http://secunia.com/advisories/25650" source="SECUNIA" adv="1">25650</ref>
      <ref url="http://secunia.com/advisories/25648" source="SECUNIA" adv="1">25648</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10002" source="OVAL">oval:org.mitre.oval:def:10002</ref>
      <ref url="http://osvdb.org/35378" source="OSVDB">35378</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc" source="SGI">20070602-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openoffice" name="openoffice">
        <vers prev="1" num="2.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0246" published="2007-05-29" name="CVE-2007-0246" modified="2012-11-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">plugins/scmcvs/www/cvsweb.php in the CVSWeb CGI in GForge 4.5.16 before 20070524, aka gforge-plugin-scmcvs, allows remote attackers to execute arbitrary commands via shell metacharacters in the PATH_INFO.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/25416" source="SECUNIA" patch="1" adv="1">25416</ref>
      <ref url="http://secunia.com/advisories/25395" source="SECUNIA" patch="1" adv="1">25395</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34510" source="XF">gforge-cvsweb-command-execution(34510)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1942" source="VUPEN">ADV-2007-1942</ref>
      <ref url="http://www.securityfocus.com/bid/24141" source="BID">24141</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1297" source="DEBIAN">DSA-1297</ref>
      <ref url="http://osvdb.org/36526" source="OSVDB">36526</ref>
      <ref url="http://gforge.org/scm/viewvc.php/branches/Branch_4_5/gforge/plugins/scmcvs/www/cvsweb.php?root=gforge&amp;r1=5849&amp;r2=6038&amp;pathrev=6038" source="CONFIRM">http://gforge.org/scm/viewvc.php/branches/Branch_4_5/gforge/plugins/scmcvs/www/cvsweb.php?root=gforge&amp;r1=5849&amp;r2=6038&amp;pathrev=6038</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34510" source="XF">gforge-cvsweb-code-execution(34510)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gforge" name="gforge">
        <vers prev="1" num="4.5.16"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0247" published="2007-01-16" name="CVE-2007-0247" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory listing responses, possibly related to the (1) ftpListingFinish and (2) ftpHtmlifyListEntry functions.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31523" source="XF">squid-multiple-dos(31523)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0199" source="VUPEN" adv="1">ADV-2007-0199</ref>
      <ref url="http://www.ubuntu.com/usn/usn-414-1" source="UBUNTU">USN-414-1</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.6/squid-2.6.STABLE7-RELEASENOTES.html#s12" source="CONFIRM">http://www.squid-cache.org/Versions/v2/2.6/squid-2.6.STABLE7-RELEASENOTES.html#s12</ref>
      <ref url="http://www.squid-cache.org/bugs/show_bug.cgi?id=1857" source="CONFIRM">http://www.squid-cache.org/bugs/show_bug.cgi?id=1857</ref>
      <ref url="http://www.securityfocus.com/bid/22079" source="BID">22079</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_12_squid.html" source="SUSE">SUSE-SA:2007:012</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:026" source="MANDRIVA">MDKSA-2007:026</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200701-22.xml" source="GENTOO">GLSA-200701-22</ref>
      <ref url="http://secunia.com/advisories/23946" source="SECUNIA" adv="1">23946</ref>
      <ref url="http://secunia.com/advisories/23921" source="SECUNIA" adv="1">23921</ref>
      <ref url="http://secunia.com/advisories/23889" source="SECUNIA" adv="1">23889</ref>
      <ref url="http://secunia.com/advisories/23837" source="SECUNIA" adv="1">23837</ref>
      <ref url="http://secunia.com/advisories/23810" source="SECUNIA" adv="1">23810</ref>
      <ref url="http://secunia.com/advisories/23805" source="SECUNIA" adv="1">23805</ref>
      <ref url="http://secunia.com/advisories/23767" source="SECUNIA" adv="1">23767</ref>
      <ref url="http://osvdb.org/39839" source="OSVDB">39839</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.6.stable1"/>
        <vers num="2.6.stable2"/>
        <vers num="2.6.stable3"/>
        <vers num="2.6.stable4"/>
        <vers num="2.6.stable5"/>
        <vers num="2.6.stable6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0248" published="2007-01-16" name="CVE-2007-0248" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The aclMatchExternal function in Squid before 2.6.STABLE7 allows remote attackers to cause a denial of service (crash) by causing an external_acl queue overload, which triggers an infinite loop.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23767" source="SECUNIA" patch="1" adv="1">23767</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0199" source="VUPEN">ADV-2007-0199</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.6/squid-2.6.STABLE7-RELEASENOTES.html#s12" source="CONFIRM">http://www.squid-cache.org/Versions/v2/2.6/squid-2.6.STABLE7-RELEASENOTES.html#s12</ref>
      <ref url="http://www.squid-cache.org/bugs/show_bug.cgi?id=1848" source="CONFIRM">http://www.squid-cache.org/bugs/show_bug.cgi?id=1848</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31525" source="XF">squid-externalacl-dos(31525)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-414-1" source="UBUNTU">USN-414-1</ref>
      <ref url="http://www.securityfocus.com/bid/22203" source="BID">22203</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_12_squid.html" source="SUSE">SUSE-SA:2007:012</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:026" source="MANDRIVA">MDKSA-2007:026</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200701-22.xml" source="GENTOO">GLSA-200701-22</ref>
      <ref url="http://secunia.com/advisories/23946" source="SECUNIA">23946</ref>
      <ref url="http://secunia.com/advisories/23921" source="SECUNIA">23921</ref>
      <ref url="http://secunia.com/advisories/23889" source="SECUNIA">23889</ref>
      <ref url="http://secunia.com/advisories/23805" source="SECUNIA">23805</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.6.stable6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0249" published="2007-01-16" name="CVE-2007-0249" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Nwom topsites 3.0 allows remote attackers to inject arbitrary web script or HTML via the o parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22012" source="BID">22012</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456636/100/0/threaded" source="BUGTRAQ">20070111 Nwom topsites v3.0</ref>
      <ref url="http://osvdb.org/33461" source="OSVDB">33461</ref>
      <ref url="http://securityreason.com/securityalert/2149" source="SREASON">2149</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nwom" name="nwom_topsites">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0250" published="2007-01-16" name="CVE-2007-0250" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">index.php in Nwom topsites 3.0 allows remote attackers to obtain potentially sensitive information via a ' (quote) character in the o parameter, which forces a SQL error.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22012" source="BID">22012</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456636/100/0/threaded" source="BUGTRAQ">20070111 Nwom topsites v3.0</ref>
      <ref url="http://osvdb.org/33462" source="OSVDB">33462</ref>
      <ref url="http://securityreason.com/securityalert/2149" source="SREASON">2149</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nwom" name="nwom_topsites">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0251" published="2007-01-16" name="CVE-2007-0251" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Integer underflow in the DecodeGRE function in src/decode.c in Snort 2.6.1.2 allows remote attackers to trigger dereferencing of certain memory locations via crafted GRE packets, which may cause corruption of log files or writing of sensitive information into log files.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0152" source="VUPEN">ADV-2007-0152</ref>
      <ref url="http://www.snort.org/got_source/source.html" source="CONFIRM">http://www.snort.org/got_source/source.html</ref>
      <ref url="http://www.securityfocus.com/bid/22004" source="BID">22004</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456598/100/0/threaded" source="BUGTRAQ">20070111 Calyptix Security Advisory CX-2007-001 - Snort 2.6.1.2 Integer Underflow Vulnerability</ref>
      <ref url="http://osvdb.org/33464" source="OSVDB">33464</ref>
      <ref url="http://osvdb.org/32095" source="OSVDB">32095</ref>
      <ref url="http://labs.calyptix.com/advisories/CX-2007-01.txt" source="MISC">http://labs.calyptix.com/advisories/CX-2007-01.txt</ref>
      <ref url="http://securitytracker.com/id?1017507" source="SECTRACK">1017507</ref>
      <ref url="http://securityreason.com/securityalert/2165" source="SREASON">2165</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snort" name="snort">
        <vers num="2.6.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0252" published="2007-01-16" name="CVE-2007-0252" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in easy-content filemanager allows remote attackers to upload or modify arbitrary files via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456622/100/0/threaded" source="BUGTRAQ">20070111 easy-content filemanager</ref>
      <ref url="http://osvdb.org/33463" source="OSVDB">33463</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easy-content_filemanager" name="easy-content_filemanager">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0253" published="2007-01-16" name="CVE-2007-0253" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">** DISPUTED **  Unspecified vulnerability in the grsecurity patch has unspecified impact and remote attack vectors, a different vulnerability than the expand_stack vulnerability from the Digital Armaments 20070110 pre-advisory.  NOTE: the grsecurity developer has disputed this issue, stating that "the function they claim the vulnerability to be in is a trivial function, which can, and has been, easily checked for any supposed vulnerabilities."  The developer also cites a past disclosure that was not proven.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.digitalarmaments.com/news_news.shtml" source="MISC" adv="1">http://www.digitalarmaments.com/news_news.shtml</ref>
      <ref url="http://grsecurity.net/news.php#digitalfud" source="MISC">http://grsecurity.net/news.php#digitalfud</ref>
      <ref url="http://forums.grsecurity.net/viewtopic.php?t=1646" source="MISC" adv="1">http://forums.grsecurity.net/viewtopic.php?t=1646</ref>
    </refs>
    <vuln_soft>
      <prod vendor="grsecurity" name="grsecurity_kernel_patch">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0254" published="2007-01-16" name="CVE-2007-0254" modified="2010-09-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in the errors_create_window function in errors.c in xine-ui allows attackers to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22002" source="BID">22002</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456590/100/0/threaded" source="BUGTRAQ">20070111 Xine-ui format string Vulnerabilties.</ref>
      <ref url="http://osvdb.org/31594" source="OSVDB">31594</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31505" source="XF">xineui-errorscreatewindow-format-string(31505)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:154" source="MANDRIVA">MDKSA-2007:154</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:027" source="MANDRIVA">MDKSA-2007:027</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200701-18.xml" source="GENTOO">GLSA-200701-18</ref>
      <ref url="http://secunia.com/advisories/23931" source="SECUNIA">23931</ref>
      <ref url="http://secunia.com/advisories/23891" source="SECUNIA">23891</ref>
      <ref url="http://secunia.com/advisories/23709" source="SECUNIA">23709</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xine" name="xine-ui">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0255" published="2007-01-16" name="CVE-2007-0255" modified="2010-09-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">XINE 0.99.4 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a certain M3U file that contains a long #EXTINF line and contains format string specifiers in an invalid udp:// URI, possibly a variant of CVE-2007-0017.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456523/100/0/threaded" source="BUGTRAQ">20070110 VLC Format String Vulnerability also in XINE</ref>
      <ref url="http://osvdb.org/31666" source="OSVDB">31666</ref>
      <ref url="http://www.securityfocus.com/bid/22252" source="BID">22252</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:154" source="MANDRIVA">MDKSA-2007:154</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:027" source="MANDRIVA">MDKSA-2007:027</ref>
      <ref url="http://secunia.com/advisories/23931" source="SECUNIA">23931</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xine" name="xine">
        <vers num="0.99.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0256" published="2007-01-16" name="CVE-2007-0256" modified="2012-01-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">VideoLAN VLC 0.8.6a allows remote attackers to cause a denial of service (application crash) via a crafted .wmv file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22003" source="BID">22003</ref>
      <ref url="http://wiki.videolan.org/Changelog/0.8.6b" source="CONFIRM">http://wiki.videolan.org/Changelog/0.8.6b</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14698" source="OVAL">oval:org.mitre.oval:def:14698</ref>
      <ref url="http://osvdb.org/39022" source="OSVDB">39022</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/22003.py" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/22003.py</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31515" source="XF">vlcmediaplayer-wmv-dos(31515)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="videolan" name="vlc_media_player">
        <vers num="0.8.6a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0257" published="2007-01-16" name="CVE-2007-0257" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">** DISPUTED **  Unspecified vulnerability in the expand_stack function in grsecurity PaX allows local users to gain privileges via unspecified vectors. NOTE: the grsecurity developer has disputed this issue, stating that "the function they claim the vulnerability to be in is a trivial function, which can, and has been, easily checked for any supposed vulnerabilities."  The developer also cites a past disclosure that was not proven.  As of 20070120, the original researcher has released demonstration code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0155" source="VUPEN">ADV-2007-0155</ref>
      <ref url="http://www.securityfocus.com/bid/22014" source="BID">22014</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462302/100/100/threaded" source="BUGTRAQ">20070309 Re: Digital Armaments Security Advisory 20.01.2007: Grsecurity Kernel PaX Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457509/100/0/threaded" source="BUGTRAQ">20070120 Digital Armaments Security Advisory 20.01.2007: Grsecurity Kernel PaX Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456722/100/0/threaded" source="BUGTRAQ">20070112 Lies? [Was: Re: Digital Armaments Security Pre-Advisory11.01.2007: Grsecurity Kernel PaX - Local root vulnerability]</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456626/100/0/threaded" source="BUGTRAQ" adv="1">20070111 Digital Armaments Security Pre-Advisory 11.01.2007: Grsecurity Kernel PaX - Local root vulnerability</ref>
      <ref url="http://www.digitalarmaments.com/pre2007-00018659.html" source="MISC" adv="1">http://www.digitalarmaments.com/pre2007-00018659.html</ref>
      <ref url="http://www.digitalarmaments.com/news_news.shtml" source="MISC" adv="1">http://www.digitalarmaments.com/news_news.shtml</ref>
      <ref url="http://securitytracker.com/id?1017509" source="SECTRACK">1017509</ref>
      <ref url="http://secunia.com/advisories/23713" source="SECUNIA">23713</ref>
      <ref url="http://osvdb.org/32727" source="OSVDB">32727</ref>
      <ref url="http://grsecurity.net/news.php#digitalfud" source="MISC">http://grsecurity.net/news.php#digitalfud</ref>
      <ref url="http://forums.grsecurity.net/viewtopic.php?t=1646" source="MISC" adv="1">http://forums.grsecurity.net/viewtopic.php?t=1646</ref>
    </refs>
    <vuln_soft>
      <prod vendor="grsecurity" name="grsecurity_kernel_patch">
        <vers num="1.9.4"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.7"/>
        <vers num="2.1.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0258" published="2007-01-16" name="CVE-2007-0258" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in (1) Fastilo 2.0 and (2) Open Solution Quick.Cart 2.0 allows remote attackers to inject arbitrary web script or HTML via the p parameter.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0157" source="VUPEN">ADV-2007-0157</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0156" source="VUPEN">ADV-2007-0156</ref>
      <ref url="http://www.securityfocus.com/bid/22007" source="BID">22007</ref>
      <ref url="http://secunia.com/advisories/23738" source="SECUNIA" adv="1">23738</ref>
      <ref url="http://secunia.com/advisories/23733" source="SECUNIA" adv="1">23733</ref>
      <ref url="http://osvdb.org/32731" source="OSVDB">32731</ref>
      <ref url="http://osvdb.org/32730" source="OSVDB">32730</ref>
      <ref url="http://14house.blogspot.com/2007/01/fastilo-open-source-shopping-cart-vuln.html" source="MISC">http://14house.blogspot.com/2007/01/fastilo-open-source-shopping-cart-vuln.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31475" source="XF">quickcart-p-xss(31475)</ref>
      <ref url="http://www.securityfocus.com/bid/21971" source="BID">21971</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fastilo" name="fastilo">
        <vers num="2.0"/>
      </prod>
      <prod vendor="opensolution" name="quick.car">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0259" published="2007-01-16" name="CVE-2007-0259" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Ezboxx Portal System Beta 0.7.6 and earlier allows remote attackers to obtain sensitive information via a invalid cat parameter to boxx/knowledgebase.asp, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0208" source="VUPEN">ADV-2007-0208</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456699/100/0/threaded" source="BUGTRAQ">20070111 Ezboxx multiple vulnerabilities.</ref>
      <ref url="http://osvdb.org/33470" source="OSVDB">33470</ref>
      <ref url="http://osvdb.org/32829" source="OSVDB">32829</ref>
      <ref url="http://www.bugsec.com/articles.php?Security=20" source="MISC">http://www.bugsec.com/articles.php?Security=20</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ezboxx" name="ezboxx_portal_system">
        <vers prev="1" num="beta_0.7.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0260" published="2007-01-16" name="CVE-2007-0260" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in index.php in Naig 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the this_path parameter.  NOTE: a reliable third party disputes this vulnerability because this_path is defined before use.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456744/100/0/threaded" source="BUGTRAQ">20070112 Naig &lt;= 0.5.2 (this_path) Remote File Include Vulnerability</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001239.html" source="VIM">20070112 Fwd: Naig &lt;= 0.5.2 (this_path) Remote File Include Vulnerability</ref>
      <ref url="http://osvdb.org/33472" source="OSVDB">33472</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456785/100/0/threaded" source="BUGTRAQ">20070113 Re: Naig &lt;= 0.5.2 (this_path) Remote File Include Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/2145" source="SREASON">2145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="naig" name="naig">
        <vers num="0.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0261" published="2007-01-16" name="CVE-2007-0261" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, as demonstrated by changing an administrative password via the changeup task, and by uploading PHP code via the imagefile parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22025" source="BID">22025</ref>
      <ref url="http://osvdb.org/32817" source="OSVDB">32817</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31535" source="XF">snews-image-file-upload(31535)</ref>
      <ref url="http://secunia.com/advisories/23746" source="SECUNIA">23746</ref>
      <ref url="http://milw0rm.com/exploits/3116" source="MILW0RM">3116</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snews" name="snews">
        <vers num="1.5.29"/>
        <vers num="1.5.30"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0262" published="2007-01-16" name="CVE-2007-0262" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attackers to obtain sensitive information via an invalid m[] parameter, as demonstrated by obtaining the path, and obtaining certain SQL information such as the table prefix.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456731/100/0/threaded" source="BUGTRAQ">20070112 Wordpress disclosure of Table Prefix Weakness</ref>
      <ref url="http://osvdb.org/33458" source="OSVDB">33458</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="2.0.6"/>
        <vers num="2.1" edition="alpha_3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0263" published="2007-01-16" name="CVE-2007-0263" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:C/A:C)" CVSS_score="7.1" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="4.9" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in Total Commander before 6.5.6 allows user-assisted remote attackers to delete arbitrary files and corrupt a filesystem via a crafted RAR file.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22033" source="BID" patch="1">22033</ref>
      <ref url="http://www.ghisler.com/whatsnew.htm" source="MISC">http://www.ghisler.com/whatsnew.htm</ref>
      <ref url="http://osvdb.org/39837" source="OSVDB">39837</ref>
    </refs>
    <vuln_soft>
      <prod vendor="total_commander" name="total_commander">
        <vers prev="1" num="6.5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0264" published="2007-01-16" name="CVE-2007-0264" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.7" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">Buffer overflow in Winzip32.exe in WinZip 9.0 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long command line argument.  NOTE: this issue may cross privilege boundaries if an application automatically invokes Winzip32.exe for untrusted input filenames, as in the case of a file upload application.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
WinZip, WinZip, 9.0 SR1</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22020" source="BID">22020</ref>
      <ref url="http://osvdb.org/39800" source="OSVDB">39800</ref>
    </refs>
    <vuln_soft>
      <prod vendor="winzip" name="winzip">
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0265" published="2007-01-16" name="CVE-2007-0265" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Ezboxx Portal System Beta 0.7.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the pic parameter to custom/piczoom.asp, (2) the nocatname parameter to boxx/user-upload.asp, or (3) the iid parameter to indexes/newscomments.asp.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0208" source="VUPEN">ADV-2007-0208</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456699/100/0/threaded" source="BUGTRAQ">20070111 Ezboxx multiple vulnerabilities.</ref>
      <ref url="http://osvdb.org/33469" source="OSVDB">33469</ref>
      <ref url="http://osvdb.org/33468" source="OSVDB">33468</ref>
      <ref url="http://osvdb.org/33467" source="OSVDB">33467</ref>
      <ref url="http://osvdb.org/32828" source="OSVDB">32828</ref>
      <ref url="http://osvdb.org/32827" source="OSVDB">32827</ref>
      <ref url="http://osvdb.org/32826" source="OSVDB">32826</ref>
      <ref url="http://www.bugsec.com/articles.php?Security=20" source="MISC">http://www.bugsec.com/articles.php?Security=20</ref>
      <ref url="http://secunia.com/advisories/23759" source="SECUNIA">23759</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ezboxx" name="portal_system_beta">
        <vers prev="1" num="0.7.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0266" published="2007-01-16" name="CVE-2007-0266" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in boxx/ShowAppendix.asp in Ezboxx Portal System Beta 0.7.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the iid parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0208" source="VUPEN">ADV-2007-0208</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456699/100/0/threaded" source="BUGTRAQ">20070111 Ezboxx multiple vulnerabilities.</ref>
      <ref url="http://osvdb.org/33466" source="OSVDB">33466</ref>
      <ref url="http://osvdb.org/32825" source="OSVDB">32825</ref>
      <ref url="http://www.bugsec.com/articles.php?Security=20" source="MISC">http://www.bugsec.com/articles.php?Security=20</ref>
      <ref url="http://secunia.com/advisories/23759" source="SECUNIA">23759</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ezboxx" name="ezboxx_portal_system">
        <vers prev="1" num="beta_0.7.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0267" published="2007-01-16" name="CVE-2007-0267" modified="2011-06-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="3.9" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">The ufs_lookup function in the Mac OS X 10.4.8 and FreeBSD 6.1 kernels allows local users to cause a denial of service (kernel panic) and possibly corrupt other filesystems by mounting a crafted UNIX File System (UFS) DMG image that contains a corrupted directory entry (struct direct), related to the ufs_dirbad function.  NOTE: a third party states that the FreeBSD issue does not cross privilege boundaries.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN" adv="1">ADV-2007-0930</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0171" source="VUPEN" adv="1">ADV-2007-0171</ref>
      <ref url="http://www.securitytracker.com/id?1017751" source="SECTRACK">1017751</ref>
      <ref url="http://www.securityfocus.com/bid/22036" source="BID">22036</ref>
      <ref url="http://www.osvdb.org/32686" source="OSVDB">32686</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA" adv="1">24479</ref>
      <ref url="http://secunia.com/advisories/23721" source="SECUNIA" adv="1">23721</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-12-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-12-01-2007.html</ref>
      <ref url="http://lists.freebsd.org/pipermail/freebsd-security/2007-January/004218.html" source="MLIST">[freebsd-security] 20070114 MOAB advisories</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE">APPLE-SA-2007-03-13</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8"/>
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0268" published="2007-01-16" name="CVE-2007-0268" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unknown impact and attack vectors related to (1) the Advanced Queuing component and sys.dbms_aqsys.dbms_aq privileges (DB01), (2) Advanced Replication and sys.dbms_repcat_untrusted (DB07), and (3) Oracle Text and ctxload (DB15).  NOTE: Oracle has not publicly claims by reliable researchers that DB01 is for SQL injection in the SYS.DBMS_AQ_INV package, and DB07 is for a buffer overflow in the UNREGISTER_SNAPSHOT procedure in the DBMS_REPCAT_UNTRUSTED package.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/221788" source="CERT-VN" patch="1">VU#221788</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID" patch="1">22083</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458475/100/100/threaded" source="BUGTRAQ">20070129 Re: Re: Oracle Buffer Overflows in DBMS_CAPTURE_ADM_INTERNAL</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458005/100/0/threaded" source="BUGTRAQ">20070124 Oracle Buffer Overflow in DBMS_REPCAT_UNTRUSTED.UNREGISTER_SNAPSHOT</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_aq_inv.html" source="MISC">http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_aq_inv.html</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
      <ref url="http://osvdb.org/32921" source="OSVDB">32921</ref>
      <ref url="http://osvdb.org/32913" source="OSVDB">32913</ref>
      <ref url="http://osvdb.org/32907" source="OSVDB">32907</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
        <vers num="9.0.1.5"/>
        <vers num="9.2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0269" published="2007-01-16" name="CVE-2007-0269" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and attack vectors related to the Change Data Capture and sys.dbms_cdc_subscribe privileges, aka DB02.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://osvdb.org/32908" source="OSVDB">32908</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
        <vers num="10.2.0.3"/>
        <vers num="9.2.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0270" published="2007-01-16" name="CVE-2007-0270" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Buffer overflow in SYS.DBMS_DRS in Oracle Database 9.2.0.7 and 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via the GET_PROPERTY function in SYS.DBMS_DRS, aka DB03.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/474050/100/0/threaded" source="BUGTRAQ">20070718 Oracle Database Buffer overflow vulnerabilities in procedure DBMS_DRS.GET_PROPERTY (DB03)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458036/100/0/threaded" source="BUGTRAQ">20070124 Oracle Buffer Overflow in DBMS_DRS.GET_PROPERTY</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://www.appsecinc.com/resources/alerts/oracle/2007-04.shtml" source="MISC">http://www.appsecinc.com/resources/alerts/oracle/2007-04.shtml</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
      <ref url="http://osvdb.org/32909" source="OSVDB">32909</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.4"/>
        <vers num="9.2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0271" published="2007-01-16" name="CVE-2007-0271" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Database 9.0.1.5 and 9.2.0.7 has unknown impact and attack vectors related to the Log Miner component and sys.dbms_log_mnr privileges, aka DB04.  NOTE: Oracle has not disputed a reliable researcher claim that this is a buffer overflow in the ADD_LOGFILE procedure for the SYS.DBMS_LOGMNR package that allows code execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458475/100/100/threaded" source="BUGTRAQ">20070129 Re: Re: Oracle Buffer Overflows in DBMS_CAPTURE_ADM_INTERNAL</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458006/100/0/threaded" source="BUGTRAQ">20070124 Oracle Buffer Overflow in DBMS_LOGMNR.ADD_LOGFILE</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://www.appsecinc.com/resources/alerts/oracle/2007-01.shtml" source="MISC">http://www.appsecinc.com/resources/alerts/oracle/2007-01.shtml</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
      <ref url="http://osvdb.org/32910" source="OSVDB">32910</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="9.0.1.5"/>
        <vers num="9.2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0272" published="2007-01-16" name="CVE-2007-0272" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="8.0" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in MDSYS.MD in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via unspecified vectors involving certain public procedures, aka DB05.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/474047/100/0/threaded" source="BUGTRAQ">20070718 Oracle Database Buffer overflows and Denial of service vulnerabilities in public procedures of MDSYS.MD (DB12)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458038/100/0/threaded" source="BUGTRAQ">20070124 Oracle Multiple Buffer Overflows and DoS attacks in public procedures of MDSYS.MD</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://www.appsecinc.com/resources/alerts/oracle/2007-05.shtml" source="MISC">http://www.appsecinc.com/resources/alerts/oracle/2007-05.shtml</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
      <ref url="http://osvdb.org/32911" source="OSVDB">32911</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.4"/>
        <vers num="8.1.7.4"/>
        <vers num="9.0.1.5"/>
        <vers num="9.2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0273" published="2007-01-16" name="CVE-2007-0273" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and attack vectors related to XMLDB, aka DB06.  NOTE: as of 20070123, Oracle has not disputed claims by a reliable researcher that DB06 is for multiple cross-site scripting (XSS) vulnerabilities.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_xmldb_css2.html" source="MISC">http://www.red-database-security.com/advisory/oracle_xmldb_css2.html</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
      <ref url="http://osvdb.org/32912" source="OSVDB">32912</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
        <vers num="10.2.0.3"/>
        <vers num="9.0.1.5"/>
        <vers num="9.2.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0274" published="2007-01-16" name="CVE-2007-0274" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database 9.2.0.7 and 10.1.0.5 have unknown impact and attack vectors related to (1) Export and sys.dbms_logrep_util (DB08), and (2) Oracle Streams and sys.dbms_capture_adm_internal privileges (DB09).  NOTE: Oracle has not disputed reliable researcher claims that DB08 is for a buffer overflow in the GET_OBJECT_NAME procedure in the DBMS_LOGREP_UTIL package, and DB09 is for buffer overflows in the CREATE_CAPTURE, ALTER_CAPTURE, and ABORT_TABLE_INSTANTIATION procedures in SYS.DBMS_CAPTURE_ADM_INTERNAL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID" patch="1">22083</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458475/100/100/threaded" source="BUGTRAQ">20070129 Re: Re: Oracle Buffer Overflows in DBMS_CAPTURE_ADM_INTERNAL</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458126/100/0/threaded" source="BUGTRAQ">20070125 Re: Oracle Buffer Overflow in DBMS_LOGREP_UTIL.GET_OBJECT_NAME</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458112/100/100/threaded" source="BUGTRAQ">20070125 Re: Oracle Buffer Overflows in DBMS_CAPTURE_ADM_INTERNAL</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458041/100/0/threaded" source="BUGTRAQ">20070124 Oracle Buffer Overflows in DBMS_CAPTURE_ADM_INTERNAL</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458037/100/0/threaded" source="BUGTRAQ">20070124 Oracle Buffer Overflow in DBMS_LOGREP_UTIL.GET_OBJECT_NAME</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
      <ref url="http://osvdb.org/32915" source="OSVDB">32915</ref>
      <ref url="http://osvdb.org/32914" source="OSVDB">32914</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
        <vers num="9.2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0275" published="2007-01-16" name="CVE-2007-0275" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Oracle Reports Web Cartridge (RWCGI60) in the Workflow Cartridge component, as used in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaboration Suite 10.1.2; and Oracle E-Business Suite and Applications 11.5.10CU2; allows remote authenticated users to inject arbitrary HTML or web script via the genuser parameter to rwcgi60, aka OWF01.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT">TA07-017A</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457193/100/0/threaded" source="BUGTRAQ">20070117 [ISecAuditors Security Advisories] Oracle Reports Web Cartridge (RWCGI60) vulnerable to XSS</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
      <ref url="http://osvdb.org/32906" source="OSVDB">32906</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.0.2"/>
        <vers num="10.1.2.2"/>
        <vers num="9.0.4.3"/>
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="10.1.2"/>
      </prod>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
        <vers num="10.2.0.3"/>
        <vers num="9.2.0.8"/>
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0276" published="2007-01-16" name="CVE-2007-0276" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4 and 9.0.1.5 have unknown impact and attack vectors related to (1) Advanced Security Option and oklist or okdstry (DB10), (2) Oracle Net Services (DB13), and (3) Recovery Manager and oklist (DB16).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://osvdb.org/32922" source="OSVDB">32922</ref>
      <ref url="http://osvdb.org/32919" source="OSVDB">32919</ref>
      <ref url="http://osvdb.org/32916" source="OSVDB">32916</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="8.1.7.4"/>
        <vers num="9.0.1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0277" published="2007-01-16" name="CVE-2007-0277" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Database client-only 10.1.0.4 has unknown impact and attack vectors related to the Export component and expdp or impdp, aka DB11.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://osvdb.org/32917" source="OSVDB">32917</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0278" published="2007-01-16" name="CVE-2007-0278" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unknown impact and attack vectors related to (1) NLS Runtime and lmsgen (DB12), and (2) Oracle Text and ctxkbtc (DB14).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://osvdb.org/32920" source="OSVDB">32920</ref>
      <ref url="http://osvdb.org/32918" source="OSVDB">32918</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
        <vers num="8.1.7.4"/>
        <vers num="9.0.1.5"/>
        <vers num="9.2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0279" published="2007-01-16" name="CVE-2007-0279" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle HTTP Server 9.2.0.8 and Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors, aka (1) OHS01, (2) OHS02, (3) OHS05, (4) OHS06, and (5) OHS07.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://osvdb.org/32887" source="OSVDB">32887</ref>
      <ref url="http://osvdb.org/32886" source="OSVDB">32886</ref>
      <ref url="http://osvdb.org/32885" source="OSVDB">32885</ref>
      <ref url="http://osvdb.org/32882" source="OSVDB">32882</ref>
      <ref url="http://osvdb.org/32881" source="OSVDB">32881</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2"/>
      </prod>
      <prod vendor="oracle" name="http_server">
        <vers num="9.2.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0280" published="2007-01-16" name="CVE-2007-0280" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.3, 10.1.2.0.0, 10.1.2.0.2, and 10.1.2.2; and Collaboration Suite 9.0.4.2 and 10.1.2; has unknown impact and attack vectors related to the Oracle Process Mgmt &amp; Notification component, aka OPMN01.   NOTE: as of 20070123, Oracle has not disputed claims by a reliable researcher that OPMN01 is for a buffer overflow in Oracle Notification Service (ONS).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_buffer_overflow_ons.html" source="MISC">http://www.red-database-security.com/advisory/oracle_buffer_overflow_ons.html</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
      <ref url="http://osvdb.org/32905" source="OSVDB">32905</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.0.2"/>
        <vers num="10.1.2.2"/>
        <vers num="9.0.4.3"/>
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="10.1.2"/>
        <vers num="9.0.4.2"/>
      </prod>
      <prod vendor="oracle" name="http_server">
        <vers num="9.0.1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0281" published="2007-01-16" name="CVE-2007-0281" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle HTTP Server 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.0, 10.1.2.0.1, 10.1.2.0.2, 10.1.2.1, and 10.1.3.0; and Collaboration Suite 9.0.4.2 and 10.1.2; have unknown impact and attack vectors related to the Oracle HTTP Server, aka (1) OHS03 and (2) OHS04.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://osvdb.org/32884" source="OSVDB">32884</ref>
      <ref url="http://osvdb.org/32883" source="OSVDB">32883</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.0.2"/>
        <vers num="10.1.2.2"/>
        <vers num="9.0.4.3"/>
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="10.1.2"/>
        <vers num="9.0.4.2"/>
      </prod>
      <prod vendor="oracle" name="http_server">
        <vers num="9.0.1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0282" published="2007-01-16" name="CVE-2007-0282" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="3.2" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.1" CVSS_base_score="3.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.2 and 10.1.2.0.0, and Collaboration Suite 9.0.4.2 has unknown impact and attack vectors related to the Oracle Process Mgmt &amp; Notification component, aka OPMN02.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.0.0"/>
        <vers num="9.0.4.3"/>
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="9.0.4.2"/>
      </prod>
      <prod vendor="oracle" name="http_server">
        <vers num="9.0.1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0283" published="2007-01-16" name="CVE-2007-0283" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Application Server 9.0.4.3 and Collaboration Suite 9.0.4.2 has unknown impact and attack vectors related to Oracle Containers for J2EE, aka OC4J02.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://osvdb.org/32896" source="OSVDB">32896</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="9.0.4.3"/>
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="9.0.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0284" published="2007-01-16" name="CVE-2007-0284" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Application Server 9.0.4.3 and 10.1.2.0.0, and Collaboration Suite 9.0.4.2, have unknown impact and attack vectors related to Oracle Containers for J2EE, aka (1) OC4J03 and (2) OC4J04.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://osvdb.org/32898" source="OSVDB">32898</ref>
      <ref url="http://osvdb.org/32897" source="OSVDB">32897</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.0.0"/>
        <vers num="9.0.4.3"/>
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="9.0.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0285" published="2007-01-16" name="CVE-2007-0285" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaboration Suite 9.0.4.2 and 10.1.2; and E-Business Suite and Applications 11.5.10CU2 has unknown impact and attack vectors related to Oracle Reports Developer, aka REP01.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://osvdb.org/32894" source="OSVDB">32894</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.0.2"/>
        <vers num="10.1.2.2"/>
        <vers num="9.0.4.3"/>
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="10.1.2"/>
        <vers num="9.0.4.2"/>
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0286" published="2007-01-16" name="CVE-2007-0286" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Application Server 10.1.2.0.2 and 10.1.3.0, and Collaboration Suite 10.1.2, has unknown impact and attack vectors related to Containers for J2EE, aka OC4J07.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://osvdb.org/32901" source="OSVDB">32901</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.0.2"/>
        <vers num="10.1.3.0"/>
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="10.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0287" published="2007-01-16" name="CVE-2007-0287" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="1.7" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.1" CVSS_base_score="1.7">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Application Server 9.0.4.3, 10.1.2.0.0, and 10.1.2.0.2; and Collaboration Suite 9.0.4.2 and 10.1.2; has unknown impact and attack vectors related to Containers for J2EE, aka OC4J08.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://osvdb.org/32902" source="OSVDB">32902</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.0.0"/>
        <vers num="10.1.2.0.2"/>
        <vers num="9.0.4.3"/>
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="10.1.2"/>
        <vers num="9.0.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0288" published="2007-01-16" name="CVE-2007-0288" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="1.7" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.1" CVSS_base_score="1.7">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Application Server 10.1.4.0 has unknown impact and attack vectors related to Oracle Internet Directory, aka OID01.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://osvdb.org/32903" source="OSVDB">32903</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0289" published="2007-01-16" name="CVE-2007-0289" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Collaboration Suite 9.0.4.2 have unknown impact and attack vectors related to Oracle Containers for J2EE, aka (1) OC4J01, (2) OC4J05, and (3) OC4J06.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://osvdb.org/32900" source="OSVDB">32900</ref>
      <ref url="http://osvdb.org/32899" source="OSVDB">32899</ref>
      <ref url="http://osvdb.org/32895" source="OSVDB">32895</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="9.0.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0290" published="2007-01-16" name="CVE-2007-0290" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors related to (1) Application Object Library (APPS01), (2) Human Resources (APPS03), (3) Payables (APPS04), (4) Trading Community Architecture (APPS05), and (5) Web Applications Desktop Integrator (APPS06).</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://osvdb.org/32893" source="OSVDB">32893</ref>
      <ref url="http://osvdb.org/32892" source="OSVDB">32892</ref>
      <ref url="http://osvdb.org/32891" source="OSVDB">32891</ref>
      <ref url="http://osvdb.org/32890" source="OSVDB">32890</ref>
      <ref url="http://osvdb.org/32888" source="OSVDB">32888</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0291" published="2007-01-16" name="CVE-2007-0291" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle E-Business Suite and Applications 6.2.3 has unknown impact and attack vectors related to Oracle Exchange, aka APPS02.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://osvdb.org/32889" source="OSVDB">32889</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="6.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0292" published="2007-01-16" name="CVE-2007-0292" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Enterprise Manager 10.1.0.5 have unknown impact and attack vectors related to Oracle Agent, aka (1) EM01 and (2) EM02.  NOTE: EM05 might be related to CVE-2007-0222.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID" patch="1">22083</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
      <ref url="http://osvdb.org/32876" source="OSVDB">32876</ref>
      <ref url="http://osvdb.org/32875" source="OSVDB">32875</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="enterprise_manager">
        <vers num="10.1.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0293" published="2007-01-16" name="CVE-2007-0293" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Enterprise Manager 10.1.0.5 and 10.2.0.1 have unknown impact and attack vectors related to (1) Oracle Agent (EM03) and (2) EM04 and (3) EM05 in Enterprise Manager Console.  NOTE: EM05 might be related to CVE-2007-0222.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
      <ref url="http://osvdb.org/32879" source="OSVDB">32879</ref>
      <ref url="http://osvdb.org/32878" source="OSVDB">32878</ref>
      <ref url="http://osvdb.org/32877" source="OSVDB">32877</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="enterprise_manager">
        <vers num="10.1.0.5"/>
        <vers num="10.2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0294" published="2007-01-16" name="CVE-2007-0294" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="1.7" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.1" CVSS_base_score="1.7">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Enterprise Manager 10.2.0.1 has unknown impact and attack vectors related to Database Cloning &amp; Data Guard Management, aka EM06.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://osvdb.org/32880" source="OSVDB">32880</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="enterprise_manager">
        <vers num="10.2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0295" published="2007-01-16" name="CVE-2007-0295" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.13 and 8.47.11 has unknown impact and attack vectors in PeopleTools, aka PSE01.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="enterpriseone">
        <vers num="8.22.13"/>
        <vers num="8.47.11"/>
      </prod>
      <prod vendor="oracle" name="peoplesoft_enterprise">
        <vers num="8.22.13"/>
        <vers num="8.47.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0296" published="2007-01-16" name="CVE-2007-0296" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.13, 8.47.11, and 8.48.06 has unknown impact and attack vectors in PeopleTools, aka PSE02.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="enterpriseone">
        <vers num="8.22.13"/>
        <vers num="8.47.11"/>
        <vers num="8.48.06"/>
      </prod>
      <prod vendor="oracle" name="peoplesoft_enterprise">
        <vers num="8.22.13"/>
        <vers num="8.47.11"/>
        <vers num="8.48.06"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0297" published="2007-01-16" name="CVE-2007-0297" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.47.11 and 8.48.06 has unknown impact and attack vectors in PeopleTools, aka PSE03.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="enterpriseone">
        <vers num="8.47.11"/>
        <vers num="8.48.06"/>
      </prod>
      <prod vendor="oracle" name="peoplesoft_enterprise">
        <vers num="8.47.11"/>
        <vers num="8.48.06"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0298" published="2007-01-17" name="CVE-2007-0298" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in show.php in LunarPoll, when register_globals is enabled, allows remote attackers execute arbitrary PHP code via a URL in the PollDir parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0177" source="VUPEN">ADV-2007-0177</ref>
      <ref url="http://www.securityfocus.com/bid/22024" source="BID">22024</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456697/100/0/threaded" source="BUGTRAQ">20070112 LunarPoll (PollDir) Remote File Include Vulnerabilities</ref>
      <ref url="http://osvdb.org/31639" source="OSVDB">31639</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-January/001236.html" source="VIM">20070112 Source Verify of LunarPoll PollDir RFI</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31472" source="XF">lunarpoll-show-file-include(31472)</ref>
      <ref url="http://securitytracker.com/id?1017510" source="SECTRACK">1017510</ref>
      <ref url="http://securityreason.com/securityalert/2152" source="SREASON">2152</ref>
      <ref url="http://secunia.com/advisories/23760" source="SECUNIA">23760</ref>
      <ref url="http://milw0rm.com/exploits/3117" source="MILW0RM">3117</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dexxaboy" name="lunarpoll">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0299" published="2007-01-17" name="CVE-2007-0299" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Integer overflow in the byte_swap_sbin function in bsd/ufs/ufs/ufs_byte_order.c in Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service (kernel panic) by mounting a crafted Unix File System (UFS) DMG image, which triggers an invalid pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/515792" source="CERT-VN">VU#515792</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://www.securitytracker.com/id?1017751" source="SECTRACK">1017751</ref>
      <ref url="http://www.osvdb.org/31653" source="OSVDB">31653</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA" adv="1">24479</ref>
      <ref url="http://secunia.com/advisories/23725" source="SECUNIA" adv="1">23725</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-11-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-11-01-2007.html</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE">APPLE-SA-2007-03-13</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0300" published="2007-01-17" name="CVE-2007-0300" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in i-accueil.php in TLM CMS 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that "register_globals" is enabled.</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0176" source="VUPEN">ADV-2007-0176</ref>
      <ref url="http://www.securityfocus.com/bid/22021" source="BID">22021</ref>
      <ref url="http://secunia.com/advisories/23722" source="SECUNIA" adv="1">23722</ref>
      <ref url="http://osvdb.org/32814" source="OSVDB">32814</ref>
      <ref url="http://milw0rm.com/exploits/3118" source="MILW0RM">3118</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-January/001238.html" source="VIM">20070112 [Bogus - partly] V TLM CMS &lt;= 1.1 (i-accueil.php chemin) Remote File Include Vulnerability (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tlm_cms" name="tlm_cms">
        <vers prev="1" num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0301" published="2007-01-17" name="CVE-2007-0301" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in _admin/admin_menu.php in FdWeB Espace Membre 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that "register_globals" is enabled.</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0178" source="VUPEN">ADV-2007-0178</ref>
      <ref url="http://www.securityfocus.com/bid/22040" source="BID">22040</ref>
      <ref url="http://secunia.com/advisories/23743" source="SECUNIA" adv="1">23743</ref>
      <ref url="http://osvdb.org/32824" source="OSVDB">32824</ref>
      <ref url="http://milw0rm.com/exploits/3123" source="MILW0RM">3123</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fdweb" name="espace_membre">
        <vers num="2.01"/>
        <vers prev="1" num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0302" published="2007-01-17" name="CVE-2007-0302" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in InstantASP 4.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to (a) Logon.aspx, and the (2) Username and (3) Update parameters to (b) Members1.aspx.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0227" source="VUPEN">ADV-2007-0227</ref>
      <ref url="http://www.securityfocus.com/bid/22052" source="BID">22052</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456970/100/0/threaded" source="BUGTRAQ">20070115 InstantForum.NET Multiple Cross-Site Scripting Vulnerability</ref>
      <ref url="http://osvdb.org/32853" source="OSVDB">32853</ref>
      <ref url="http://osvdb.org/32852" source="OSVDB">32852</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31521" source="XF">instantforum-multiple-scripts-xss(31521)</ref>
      <ref url="http://securityreason.com/securityalert/2164" source="SREASON">2164</ref>
      <ref url="http://secunia.com/advisories/23787" source="SECUNIA">23787</ref>
    </refs>
    <vuln_soft>
      <prod vendor="instantasp" name="instantasp">
        <vers num="4.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0303" published="2007-01-17" name="CVE-2007-0303" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Zina 1.0rc1 and earlier have unknown impact and attack vectors related to "Potential security bugs."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0181" source="VUPEN">ADV-2007-0181</ref>
      <ref url="http://www.securityfocus.com/bid/22049" source="BID">22049</ref>
      <ref url="http://www.pancake.org/zina-changelog-12" source="CONFIRM" adv="1">http://www.pancake.org/zina-changelog-12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pancake.org" name="zina">
        <vers prev="1" num="1.0_rc1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0304" published="2007-01-17" name="CVE-2007-0304" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in duyuru.asp in MiNT Haber Sistemi 2.7 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0175" source="VUPEN">ADV-2007-0175</ref>
      <ref url="http://secunia.com/advisories/23756" source="SECUNIA" adv="1">23756</ref>
      <ref url="http://osvdb.org/32820" source="OSVDB">32820</ref>
      <ref url="http://milw0rm.com/exploits/3120" source="MILW0RM">3120</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mint" name="haber_sistemi">
        <vers prev="1" num="2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0305" published="2007-01-17" name="CVE-2007-0305" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in etkinlikbak.asp in Okul Web Otomasyon Sistemi 4.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0206" source="VUPEN">ADV-2007-0206</ref>
      <ref url="http://www.securityfocus.com/bid/22060" source="BID">22060</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456894/100/0/threaded" source="BUGTRAQ">20070115 Okul Web Otomasyon Sistemi (etkinlikbak.asp) SQL Injection Vulnerability</ref>
      <ref url="http://secunia.com/advisories/23755" source="SECUNIA" adv="1">23755</ref>
      <ref url="http://osvdb.org/32819" source="OSVDB">32819</ref>
      <ref url="http://securityreason.com/securityalert/2151" source="SREASON">2151</ref>
      <ref url="http://milw0rm.com/exploits/3135" source="MILW0RM">3135</ref>
    </refs>
    <vuln_soft>
      <prod vendor="okulsistem_okul_web" name="otomasyon_sistemi">
        <vers num="4.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0306" published="2007-01-17" name="CVE-2007-0306" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in visu_user.asp in Digiappz DigiAffiliate 1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0179" source="VUPEN">ADV-2007-0179</ref>
      <ref url="http://www.securityfocus.com/bid/22039" source="BID">22039</ref>
      <ref url="http://secunia.com/advisories/23744" source="SECUNIA">23744</ref>
      <ref url="http://osvdb.org/32818" source="OSVDB">32818</ref>
      <ref url="http://milw0rm.com/exploits/3122" source="MILW0RM">3122</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digiappz" name="digiaffiliate">
        <vers prev="1" num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0307" published="2007-01-17" name="CVE-2007-0307" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in include/common.php in Poplar Gedcom Viewer 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the env[rootPath] parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0174" source="VUPEN">ADV-2007-0174</ref>
      <ref url="http://www.securityfocus.com/bid/22038" source="BID">22038</ref>
      <ref url="http://secunia.com/advisories/23761" source="SECUNIA" adv="1">23761</ref>
      <ref url="http://osvdb.org/32807" source="OSVDB">32807</ref>
      <ref url="http://milw0rm.com/exploits/3121" source="MILW0RM">3121</ref>
    </refs>
    <vuln_soft>
      <prod vendor="poplar_gedcom_viewer" name="poplar_gedcom_viewer">
        <vers num="1.2.2"/>
        <vers prev="1" num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0308" published="2007-01-17" name="CVE-2007-0308" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Plain Black WebGUI before 7.3.4 (beta) allows remote attackers to inject arbitrary web script or HTML via Wiki Page titles.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22051" source="BID" patch="1">22051</ref>
      <ref url="http://www.plainblack.com/getwebgui/advisories/webgui-7_3_4-beta-released#BUeIjcWiQasypsJxD-YwgQ" source="CONFIRM" patch="1">http://www.plainblack.com/getwebgui/advisories/webgui-7_3_4-beta-released#BUeIjcWiQasypsJxD-YwgQ</ref>
      <ref url="http://secunia.com/advisories/23718" source="SECUNIA" adv="1">23718</ref>
      <ref url="http://osvdb.org/32813" source="OSVDB">32813</ref>
    </refs>
    <vuln_soft>
      <prod vendor="plain_black" name="webgui">
        <vers num="6.3.0"/>
        <vers num="6.4.0"/>
        <vers num="6.5.0"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
        <vers num="6.5.5"/>
        <vers num="6.5.6"/>
        <vers num="6.6.0"/>
        <vers num="6.6.1"/>
        <vers num="6.6.2"/>
        <vers num="6.6.3"/>
        <vers num="6.6.4"/>
        <vers num="6.6.5"/>
        <vers num="6.7.0"/>
        <vers num="6.7.1"/>
        <vers num="6.7.2"/>
        <vers num="6.7.3"/>
        <vers num="6.7.4"/>
        <vers num="6.7.5"/>
        <vers num="6.7.6"/>
        <vers num="6.8.1"/>
        <vers num="6.8.2"/>
        <vers num="6.8.3"/>
        <vers num="6.8.4"/>
        <vers num="6.8.5"/>
        <vers num="6.8.6"/>
        <vers num="7.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0309" published="2007-01-17" name="CVE-2007-0309" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in blocks/block-Old_Articles.php in Francisco Burzi PHP-Nuke 7.9 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cat parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22037" source="BID">22037</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456787/100/0/threaded" source="BUGTRAQ">20070113 PHP-Nuke &lt;= 7.9 Old-Articles Block "cat" SQL Injection vulnerability</ref>
      <ref url="http://www.neosecurityteam.net/advisories/PHP-Nuke--7.9-Old-Articles-Block-cat-SQL-Injection-vulnerability-31.html" source="MISC">http://www.neosecurityteam.net/advisories/PHP-Nuke--7.9-Old-Articles-Block-cat-SQL-Injection-vulnerability-31.html</ref>
      <ref url="http://securitytracker.com/id?1017511" source="SECTRACK">1017511</ref>
      <ref url="http://osvdb.org/32863" source="OSVDB">32863</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31482" source="XF">phpnuke-blockoldarticles-sql-injection(31482)</ref>
      <ref url="http://securityreason.com/securityalert/2153" source="SREASON">2153</ref>
      <ref url="http://secunia.com/advisories/23748" source="SECUNIA">23748</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers prev="1" num="7.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0310" published="2007-01-17" name="CVE-2007-0310" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BMC Remedy Action Request System 5.01.02 Patch 1267 generates different error messages for failed login attempts with a valid username than for those with an invalid username, which allows remote attackers to determine valid account names.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0204" source="VUPEN">ADV-2007-0204</ref>
      <ref url="http://www.securityfocus.com/bid/22066" source="BID">22066</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456949/100/0/threaded" source="BUGTRAQ">20070115 Remedy Action Request System 5.01.02 - User Enumeration</ref>
      <ref url="http://www.alighieri.org/advisories/advisory-remedy50102.txt" source="MISC" adv="1">http://www.alighieri.org/advisories/advisory-remedy50102.txt</ref>
      <ref url="http://secunia.com/advisories/23775" source="SECUNIA" adv="1">23775</ref>
      <ref url="http://osvdb.org/31658" source="OSVDB">31658</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31527" source="XF">rars-login-information-disclosure(31527)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457078/100/0/threaded" source="BUGTRAQ">20070116 Re: Remedy Action Request System 5.01.02 - User Enumeration</ref>
      <ref url="http://securitytracker.com/id?1017515" source="SECTRACK">1017515</ref>
      <ref url="http://securityreason.com/securityalert/2162" source="SREASON">2162</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bmc" name="remedy_action_request_system">
        <vers num="5.01.02_patch_1267"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0311" published="2007-01-17" name="CVE-2007-0311" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Texas Imperial Software WFTPD and WFTPD Pro Server 3.25 and earlier allow remote attackers to cause a denial of service (application crash) via a long SITE ADMIN command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31517" source="XF">wftpd-admn-dos(31517)</ref>
      <ref url="http://www.securityfocus.com/bid/22046" source="BID">22046</ref>
      <ref url="http://milw0rm.com/exploits/3126" source="MILW0RM">3126</ref>
    </refs>
    <vuln_soft>
      <prod vendor="texas_imperial_software" name="wftpd">
        <vers prev="1" num="3.25"/>
      </prod>
      <prod vendor="texas_imperial_software" name="wftpd_pro_server">
        <vers prev="1" num="3.25"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0312" published="2007-01-17" name="CVE-2007-0312" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">wcSimple Poll stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password hashes via a direct request for password.txt.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456982/100/0/threaded" source="BUGTRAQ">20070114 wcSimple Poll (password.txt) Remote Password Disclosure Vulnerablity</ref>
      <ref url="http://osvdb.org/33539" source="OSVDB">33539</ref>
      <ref url="http://securityreason.com/securityalert/2157" source="SREASON">2157</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wcsimple_poll" name="wcsimple_poll">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0313" published="2007-01-17" name="CVE-2007-0313" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in GONICUS System Administration (GOsa) before 2.5.8 allows remote authenticated users to modify certain settings, including the admin password, via crafted POST requests.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://oss.gonicus.de/pipermail/gosa/2007-January/002650.html" source="MLIST" patch="1">[gosa] 20070115 GOsa 2.5.8 released (security fixes!)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0207" source="VUPEN">ADV-2007-0207</ref>
      <ref url="http://secunia.com/advisories/23749" source="SECUNIA" adv="1">23749</ref>
      <ref url="http://osvdb.org/32821" source="OSVDB">32821</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31516" source="XF">gosa-unspecified-data-manipulation(31516)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gonicus" name="gonicus_system_administration">
        <vers prev="1" num="2.5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0314" published="2007-01-17" name="CVE-2007-0314" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Article System 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_DIR parameter to (1) forms.php, (2) issue_edit.php, (3) client.php, and (4) classes.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31446" source="XF">article-system-includedir-file-include(31446)</ref>
      <ref url="http://www.securityfocus.com/bid/22017" source="BID">22017</ref>
      <ref url="http://milw0rm.com/exploits/3114" source="MILW0RM">3114</ref>
    </refs>
    <vuln_soft>
      <prod vendor="article_system" name="article_system">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0315" published="2007-01-17" name="CVE-2007-0315" modified="2011-09-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple buffer overflows in FileZilla before 2.2.30a allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors related to (1) Options.cpp when storing settings in the registry, and (2) the transfer queue (QueueCtrl.cpp).  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <sols>
      <sol source="nvd">Failed exploit attempts may result in a application level denial-of-service condition.</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31500" source="XF" patch="1">filezilla-options-queuectrl-bo(31500)</ref>
      <ref url="http://www.securityfocus.com/bid/22057" source="BID" patch="1">22057</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=475423&amp;group_id=21558" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=475423&amp;group_id=21558</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0183" source="VUPEN" adv="1">ADV-2007-0183</ref>
    </refs>
    <vuln_soft>
      <prod vendor="filezilla" name="filezilla">
        <vers num="0.9.20"/>
        <vers num="0.9.21"/>
        <vers num="0.9.22"/>
        <vers num="2.2.15"/>
        <vers num="2.2.22"/>
        <vers num="2.2.23"/>
        <vers num="2.2.24"/>
        <vers num="2.2.25"/>
        <vers num="2.2.26"/>
        <vers num="2.2.26a"/>
        <vers num="2.2.27"/>
        <vers num="2.2.28"/>
        <vers num="2.2.29"/>
        <vers prev="1" num="2.2.30"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0316" published="2007-01-17" name="CVE-2007-0316" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.010 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) xuser_name parameter to shared/code/cp_authorization.php, and the (2) did parameter to public/code/cp_downloads.php, different vectors than CVE-2007-0223.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31485" source="XF">aiocp-cpdownloads-sql-injection(31485)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0190" source="VUPEN">ADV-2007-0190</ref>
      <ref url="http://www.securityfocus.com/bid/22032" source="BID">22032</ref>
      <ref url="http://www.securityfocus.com/archive/1/456742" source="BUGTRAQ">20070112 AIOCP Login Bypass Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/456741" source="BUGTRAQ">20070112 AIOCP SQL Injection Vulnerability</ref>
      <ref url="http://secunia.com/advisories/23740" source="SECUNIA" adv="1">23740</ref>
      <ref url="http://osvdb.org/32810" source="OSVDB">32810</ref>
      <ref url="http://osvdb.org/32809" source="OSVDB">32809</ref>
      <ref url="http://securityreason.com/securityalert/2166" source="SREASON">2166</ref>
    </refs>
    <vuln_soft>
      <prod vendor="all_in_one_control_panel" name="all_in_one_control_panel">
        <vers prev="1" num="1.3.010"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0317" published="2007-01-17" name="CVE-2007-0317" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the LogMessage function in FileZilla before 3.0.0-beta5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted arguments.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31497" source="XF" patch="1">filezilla-logmessage-format-string(31497)</ref>
      <ref url="http://www.securityfocus.com/bid/22063" source="BID" patch="1">22063</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=477793&amp;group_id=21558" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=477793&amp;group_id=21558</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0182" source="VUPEN">ADV-2007-0182</ref>
    </refs>
    <vuln_soft>
      <prod vendor="filezilla" name="filezilla">
        <vers num="3.0.0_beta1"/>
        <vers num="3.0.0_beta2"/>
        <vers prev="1" num="3.0.0_beta4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0318" published="2007-01-17" name="CVE-2007-0318" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The do_hfs_truncate function in Mac OS X 10.4.8 allows context-dependent attackers to cause a denial of service (kernel panic) via a crafted HFS+ filesystem in a DMG image, which causes an access of an invalid vnode structure during file removal.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0171" source="VUPEN">ADV-2007-0171</ref>
      <ref url="http://secunia.com/advisories/23742" source="SECUNIA" adv="1">23742</ref>
      <ref url="http://www.securitytracker.com/id?1017759" source="SECTRACK">1017759</ref>
      <ref url="http://www.osvdb.org/32685" source="OSVDB">32685</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-13-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-13-01-2007.html</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE">APPLE-SA-2007-03-13</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0319" published="2007-08-15" name="CVE-2007-0319" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the Motive ActiveEmailTest.EmailData (ActiveUtils EmailData) ActiveX control in ActiveUtils.dll in Motive Service Activation Manager 5.1 and Self Service Manager 5.1 and earlier allow remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/747233" source="CERT-VN">VU#747233</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/36034" source="XF">activeutils-emaildata-bo(36034)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2881" source="VUPEN">ADV-2007-2881</ref>
      <ref url="http://www.securityfocus.com/bid/25312" source="BID">25312</ref>
      <ref url="http://www.motive.com/securitybulletin_08122007.asp" source="CONFIRM">http://www.motive.com/securitybulletin_08122007.asp</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-045.mspx" source="MS">MS07-045</ref>
      <ref url="http://osvdb.org/37710" source="OSVDB">37710</ref>
      <ref url="http://securitytracker.com/id?1018571" source="SECTRACK">1018571</ref>
      <ref url="http://secunia.com/advisories/26481" source="SECUNIA">26481</ref>
    </refs>
    <vuln_soft>
      <prod vendor="motive_incorporated" name="self_service_manager">
        <vers num="5.1"/>
      </prod>
      <prod vendor="motive_incorporated" name="service_activation_manager">
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0320" published="2007-02-22" name="CVE-2007-0320" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple buffer overflows in (a) an ActiveX control (iftw.dll) and (b) Netscape plug-in (npiftw32.dll) for Macrovision (formerly InstallShield) InstallFromTheWeb allow remote attackers to execute arbitrary code via crafted HTML documents.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/181041" source="CERT-VN">VU#181041</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32645" source="XF">macrovision-installfromtheweb-activex-bo(32645)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32645" source="XF">macrovision-installfromtheweb-activex-bo(32645)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0705" source="VUPEN">ADV-2007-0705</ref>
      <ref url="http://www.securityfocus.com/bid/22672" source="BID">22672</ref>
      <ref url="http://www.kb.cert.org/vuls/id/MAPG-6UQUDP" source="MISC">http://www.kb.cert.org/vuls/id/MAPG-6UQUDP</ref>
      <ref url="http://secunia.com/advisories/24285" source="SECUNIA" adv="1">24285</ref>
      <ref url="http://osvdb.org/33531" source="OSVDB">33531</ref>
      <ref url="http://osvdb.org/33530" source="OSVDB">33530</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macrovision" name="installfromtheweb">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0321" published="2007-02-22" name="CVE-2007-0321" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in the Update Service Agent ActiveX Control in isusweb.dll for Macrovision FLEXnet Connect (formerly InstallShield Update Service) allows remote attackers to execute arbitrary code via the Download method.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/847993" source="CERT-VN">VU#847993</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32678" source="XF">macrovision-updateservice-activex-bo(32678)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0706" source="VUPEN">ADV-2007-0706</ref>
      <ref url="http://www.kb.cert.org/vuls/id/MAPG-6UERNR" source="CONFIRM">http://www.kb.cert.org/vuls/id/MAPG-6UERNR</ref>
      <ref url="http://support.installshield.com/kb/view.asp?articleid=Q113020" source="CONFIRM">http://support.installshield.com/kb/view.asp?articleid=Q113020</ref>
      <ref url="http://secunia.com/advisories/24270" source="SECUNIA">24270</ref>
      <ref url="http://osvdb.org/33532" source="OSVDB">33532</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macrovision" name="flexnet_connect">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0322" published="2007-09-05" name="CVE-2007-0322" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the Intuit QuickBooks Online Edition ActiveX control before 10 allow remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/907481" source="CERT-VN" patch="1" adv="1">VU#907481</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/36462" source="XF">quickbooks-activex-bo(36462)</ref>
      <ref url="http://www.securityfocus.com/bid/25544" source="BID">25544</ref>
      <ref url="http://secunia.com/advisories/26659" source="SECUNIA">26659</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intuit" name="quickbooks">
        <vers num="" edition=":online"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0323" published="2007-05-08" name="CVE-2007-0323" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the SetLanguage function in Research In Motion (RIM) TeamOn Import Object ActiveX control (TOImport.dll) allows remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/869641" source="CERT-VN" patch="1">VU#869641</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" source="CERT">TA07-128A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-027.mspx" source="MS" patch="1">MS07-027</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1716" source="VUPEN">ADV-2007-1716</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">HPSBST02214</ref>
      <ref url="http://osvdb.org/35873" source="OSVDB">35873</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34182" source="XF">rim-toimport-activex-bo(34182)</ref>
      <ref url="http://www.securityfocus.com/bid/23331" source="BID">23331</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">HPSBST02214</ref>
      <ref url="http://www.blackberry.com/btsc/articles/74/KB13142_f.SAL_Public.html" source="CONFIRM">http://www.blackberry.com/btsc/articles/74/KB13142_f.SAL_Public.html</ref>
      <ref url="http://secunia.com/advisories/25218" source="SECUNIA">25218</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rim" name="teamon_import_object_activex_control">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0324" published="2007-02-15" name="CVE-2007-0324" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in the LizardTech DjVu Browser Plug-in before 6.1.1 allow remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/522393" source="CERT-VN" patch="1">VU#522393</ref>
      <ref url="http://www.securityfocus.com/bid/22569" source="BID" patch="1">22569</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460197/100/0/threaded" source="BUGTRAQ" patch="1">20070215 Lizardtech DjVu Browser Plug-in - Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/24149" source="SECUNIA" patch="1" adv="1">24149</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0618" source="VUPEN">ADV-2007-0618</ref>
      <ref url="http://www.lizardtech.com/products/doc/djvupluginrelease.php" source="MISC">http://www.lizardtech.com/products/doc/djvupluginrelease.php</ref>
      <ref url="http://osvdb.org/33199" source="OSVDB">33199</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32510" source="XF">djvu-browser-multiple-bo(32510)</ref>
      <ref url="http://securityreason.com/securityalert/2259" source="SREASON">2259</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lizardtech" name="djvu_browser_plug-in">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0325" published="2007-02-20" name="CVE-2007-0325" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control in OfficeScanSetupINI.dll, as used in OfficeScan 7.0 before Build 1344, OfficeScan 7.3 before Build 1241, and Client / Server / Messaging Security 3.0 before Build 1197, allow remote attackers to execute arbitrary code via a crafted HTML document.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that OfficeScan client was installed using web deployment.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The vendor has issued a fix (7.0 Security Patch - Build 1344; 7.3 Security Patch - Build 1241).
</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/784369" source="CERT-VN">VU#784369</ref>
      <ref url="http://secunia.com/advisories/24193" source="SECUNIA" patch="1" adv="1">24193</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0638" source="VUPEN">ADV-2007-0638</ref>
      <ref url="http://www.trendmicro.com/ftp/documentation/readme/osce_70_win_en_securitypatch_1344_readme.txt" source="CONFIRM">http://www.trendmicro.com/ftp/documentation/readme/osce_70_win_en_securitypatch_1344_readme.txt</ref>
      <ref url="http://www.securitytracker.com/id?1017664" source="SECTRACK" adv="1">1017664</ref>
      <ref url="http://www.securityfocus.com/bid/22585" source="BID">22585</ref>
      <ref url="http://osvdb.org/33040" source="OSVDB">33040</ref>
      <ref url="http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034288" source="CONFIRM">http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034288</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="client-server-messaging_security">
        <vers num="3.0"/>
      </prod>
      <prod vendor="trend_micro" name="officescan_corporate_edition">
        <vers num="7.0"/>
        <vers num="7.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0326" published="2007-09-18" name="CVE-2007-0326" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the PhotoChannel Networks PNI Digital Media Photo Upload Plugin ActiveX control before 2.0.0.10, as used by multiple retailers, allow remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
PhotoChannel, PNI Digital Media Photo Upload Plugin ActiveX control, 2.0.0.10</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/854769" source="CERT-VN" patch="1">VU#854769</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3181" source="VUPEN">ADV-2007-3181</ref>
      <ref url="http://osvdb.org/37958" source="OSVDB">37958</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/36643" source="XF">photochannel-photo-upload-bo(36643)</ref>
      <ref url="http://www.securitytracker.com/id?1018701" source="SECTRACK">1018701</ref>
      <ref url="http://www.securityfocus.com/bid/25685" source="BID">25685</ref>
      <ref url="http://secunia.com/advisories/26830" source="SECUNIA">26830</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photochannel" name="pni_digital_media_upload_plugin_activex_control">
        <vers prev="1" num="2.0.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0328" published="2007-05-31" name="CVE-2007-0328" modified="2011-07-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The DWUpdateService ActiveX control in the agent (agent.exe) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allows remote attackers to execute arbitrary commands via (1) the Execute method, and obtain the exit status using (2) the GetExitCode method.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/524681" source="CERT-VN" patch="1">VU#524681</ref>
      <ref url="http://support.installshield.com/kb/view.asp?articleid=Q113020" source="CONFIRM" patch="1">http://support.installshield.com/kb/view.asp?articleid=Q113020</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34660" source="XF">macrovision-dwupdate-command-execution(34660)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/3278" source="VUPEN" adv="1">ADV-2008-3278</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2017" source="VUPEN" adv="1">ADV-2007-2017</ref>
      <ref url="http://www.blackberry.com/btsc/articles/749/KB16469_f.SAL_Public.html" source="CONFIRM">http://www.blackberry.com/btsc/articles/749/KB16469_f.SAL_Public.html</ref>
      <ref url="http://secunia.com/advisories/32842" source="SECUNIA" adv="1">32842</ref>
      <ref url="http://secunia.com/advisories/25501" source="SECUNIA" adv="1">25501</ref>
      <ref url="http://osvdb.org/36896" source="OSVDB">36896</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macrovision" name="flexnet_connect">
        <vers num="6.0"/>
      </prod>
      <prod vendor="macrovision" name="update_service">
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0329" published="2007-01-17" name="CVE-2007-0329" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">download.php in Joonas Viljanen JV2 Folder Gallery allows remote attackers to read sensitive files via a relative pathname in the file parameter, as demonstrated by config/gallerysetup.php.  NOTE: this issue might be resultant from a directory traversal vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0180" source="VUPEN">ADV-2007-0180</ref>
      <ref url="http://secunia.com/advisories/23724" source="SECUNIA" adv="1">23724</ref>
      <ref url="http://osvdb.org/32811" source="OSVDB">32811</ref>
      <ref url="http://milw0rm.com/exploits/3125" source="MILW0RM">3125</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joonas_viljanen" name="jv2_folder_gallery">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0330" published="2007-01-17" name="CVE-2007-0330" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in wsbho2k0.dll, as used by wsftpurl.exe, in Ipswitch WS_FTP 2007 Professional allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long ftp:// URL in an HTML document, and possibly other vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22062" source="BID">22062</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457097/100/0/threaded" source="BUGTRAQ">20070116 Re: Ipswitch WS_FTP 2007 Professional "wsftpurl" access violation vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456901/100/0/threaded" source="BUGTRAQ">20070114 Re: Ipswitch WS_FTP 2007 Professional "wsftpurl" access violation vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456755/100/0/threaded" source="BUGTRAQ">20070112 Ipswitch WS_FTP 2007 Professional "wsftpurl" access violation vulnerability</ref>
      <ref url="http://osvdb.org/33476" source="OSVDB">33476</ref>
      <ref url="http://securityreason.com/securityalert/2160" source="SREASON">2160</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="ws_ftp_pro">
        <vers num="2007"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0331" published="2007-01-17" name="CVE-2007-0331" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in liens.php3 in liens_dynamiques 2.1 allows remote attackers to inject arbitrary web script or HTML by using the ajouter=1 query string and the add menu.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22070" source="BID">22070</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456986/100/0/threaded" source="BUGTRAQ">20070114 liens_dynamiques xss and admin authentification</ref>
      <ref url="http://osvdb.org/33540" source="OSVDB">33540</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31528" source="XF">liensdynamiques-liens-xss(31528)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xentraz" name="liens_dynamiques">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0332" published="2007-01-17" name="CVE-2007-0332" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">(1) admin/adminlien.php3 and (2) admin/modif.php3 in liens_dynamiques 2.1 do not require authentication, which allows remote attackers to perform unauthorized administrative actions using a direct request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22068" source="BID">22068</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456986/100/0/threaded" source="BUGTRAQ">20070114 liens_dynamiques xss and admin authentification</ref>
      <ref url="http://osvdb.org/33542" source="OSVDB">33542</ref>
      <ref url="http://osvdb.org/33541" source="OSVDB">33541</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xentraz" name="liens_dynamiques">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0333" published="2007-01-17" name="CVE-2007-0333" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Agnitum Outpost Firewall PRO 4.0 allows local users to bypass access restrictions and insert Trojan horse drivers into the product's installation directory by creating links using FileLinkInformation requests with the ZwSetInformationFile function, as demonstrated by modifying SandBox.sys.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22069" source="BID">22069</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456973/100/0/threaded" source="BUGTRAQ">20070115 Outpost Bypassing Self-Protection using file links Vulnerability</ref>
      <ref url="http://www.matousec.com/info/advisories/Outpost-Bypassing-Self-Protection-using-file-links.php" source="MISC" adv="1">http://www.matousec.com/info/advisories/Outpost-Bypassing-Self-Protection-using-file-links.php</ref>
      <ref url="http://osvdb.org/33480" source="OSVDB">33480</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31529" source="XF">outpostfirewall-zwset-privilege-escalation(31529)</ref>
      <ref url="http://securityreason.com/securityalert/2163" source="SREASON">2163</ref>
    </refs>
    <vuln_soft>
      <prod vendor="agnitum" name="outpost_firewall">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":pro"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0334" published="2007-01-17" name="CVE-2007-0334" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the SIP module in InGate Firewall and SIParator before 4.5.1 allows remote attackers to conduct replay attacks on the authentication mechanism via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23737" source="SECUNIA" patch="1" adv="1">23737</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0209" source="VUPEN">ADV-2007-0209</ref>
      <ref url="http://www.securityfocus.com/bid/22080" source="BID">22080</ref>
      <ref url="http://www.ingate.com/relnote-451.php" source="CONFIRM">http://www.ingate.com/relnote-451.php</ref>
      <ref url="http://osvdb.org/32831" source="OSVDB">32831</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31546" source="XF">ingate-sip-security-bypass(31546)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ingate" name="firewall_and_siparator">
        <vers prev="1" num="4.5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0335" published="2007-01-17" name="CVE-2007-0335" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in Jax Petition Book 1.0.3.06 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the languagepack parameter to (1) jax_petitionbook.php or (2) smileys.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0220" source="VUPEN">ADV-2007-0220</ref>
      <ref url="http://www.securityfocus.com/bid/22072" source="BID">22072</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457077/100/0/threaded" source="BUGTRAQ">20070116 Re: Jax Petition Book (languagepack) Remote File Include Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456989/100/0/threaded" source="BUGTRAQ">20070115 Re: Jax Petition Book (languagepack) Remote File Include Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456981/100/0/threaded" source="BUGTRAQ">20070114 Jax Petition Book (languagepack) Remote File Include Vulnerabilities</ref>
      <ref url="http://osvdb.org/32836" source="OSVDB">32836</ref>
      <ref url="http://osvdb.org/32835" source="OSVDB">32835</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31543" source="XF">petitionbook-language-file-include(31543)</ref>
      <ref url="http://securityreason.com/securityalert/2161" source="SREASON">2161</ref>
      <ref url="http://secunia.com/advisories/23784" source="SECUNIA">23784</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jax_scripts" name="jax_petition_book">
        <vers num="1.0.3.06"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0336" published="2007-01-17" name="CVE-2007-0336" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Undercover.app/Contents/Resources/uc in Rixstep Undercover allows local users to overwrite arbitrary files, probably related to a race condition.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
      <race/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22071" source="BID">22071</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051793.html" source="FULLDISC">20070115 Rixstep aren't as leet as they thought they were</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rixstep" name="undercover">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0337" published="2007-01-17" name="CVE-2007-0337" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in sesskglogadmin.php in KGB 1.9 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the skinnn parameter, as demonstrated by invoking kg.php with a postek parameter containing PHP code, which is injected into a file in the kg directory, and then included by sesskglogadmin.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0228" source="VUPEN">ADV-2007-0228</ref>
      <ref url="http://www.securityfocus.com/bid/22065" source="BID">22065</ref>
      <ref url="http://osvdb.org/31585" source="OSVDB">31585</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31508" source="XF">kgb-sesskglogadmin-file-include(31508)</ref>
      <ref url="http://secunia.com/advisories/23768" source="SECUNIA">23768</ref>
      <ref url="http://milw0rm.com/exploits/3134" source="MILW0RM">3134</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kgb" name="kgb">
        <vers prev="1" num="1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0338" published="2007-01-17" name="CVE-2007-0338" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Dream FTP Server allows remote attackers to execute arbitrary code via a USER command with a large number of format string specifiers, which triggers the overflow during processing of the Server Log.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23731" source="SECUNIA" adv="1">23731</ref>
      <ref url="http://osvdb.org/32816" source="OSVDB">32816</ref>
      <ref url="http://milw0rm.com/exploits/3128" source="MILW0RM">3128</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bolintech" name="dreamftp_server">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0339" published="2007-01-17" name="CVE-2007-0339" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php (aka the login form) in Scriptme SMe FileMailer 1.21 allows remote attackers to execute arbitrary SQL commands via the Password field (ps parameter).  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457071/100/0/threaded" source="BUGTRAQ">20070116 [x0n3-h4ck] SmE FileMailer 1.21 Remote Sql Injextion Exploit</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001244.html" source="VIM">20070117 Source VERIFY of SMe FileMailer 1.21 SQL injection</ref>
      <ref url="http://secunia.com/advisories/23766" source="SECUNIA">23766</ref>
      <ref url="http://osvdb.org/32832" source="OSVDB">32832</ref>
      <ref url="http://securityreason.com/securityalert/2154" source="SREASON">2154</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scriptme" name="sme_filemailer">
        <vers num="1.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0340" published="2007-01-17" name="CVE-2007-0340" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in inc/header.inc.php in ThWboard 3.0b2.84-php5 and earlier allows remote attackers to execute arbitrary SQL commands via the board[styleid] parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23735" source="SECUNIA">23735</ref>
      <ref url="http://osvdb.org/32837" source="OSVDB">32837</ref>
      <ref url="http://milw0rm.com/exploits/3124" source="MILW0RM">3124</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thwboard" name="thwboard">
        <vers prev="1" num="3.0_beta_2.84" edition=""/>
        <vers prev="1" num="3.0_beta_2.84" edition=":php5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0341" published="2007-01-17" name="CVE-2007-0341" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.1 and earlier, when Microsoft Internet Explorer 6 is used, allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in a CSS style in the convcharset parameter to the top-level URI, a different vulnerability than CVE-2005-0992.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.virtuax.be/advisories/Advisory1-12012007.txt" source="MISC" patch="1" adv="1">http://www.virtuax.be/advisories/Advisory1-12012007.txt</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456726/100/0/threaded" source="BUGTRAQ">20070112 Re: xss in phpmyadmin &lt;= 2.8.1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456698/100/0/threaded" source="BUGTRAQ">20070112 xss in phpmyadmin &lt;= 2.8.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="2.8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0342" published="2007-01-17" name="CVE-2007-0342" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element with a large number in the ROWSPAN attribute, as demonstrated by a crash of OmniWeb 5.5.3 on Mac OS X 10.4.8, a different vulnerability than CVE-2006-2019.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22059" source="BID">22059</ref>
      <ref url="http://security-protocols.com/sp-x41-advisory.php" source="MISC" adv="1">http://security-protocols.com/sp-x41-advisory.php</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="2.0.4_419.3"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="build_18794"/>
      </prod>
      <prod vendor="omnigroup" name="omniweb">
        <vers num="5.5.3"/>
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0343" published="2007-01-17" name="CVE-2007-0343" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OpenBSD before 20070116 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via certain IPv6 ICMP (aka ICMP6) echo request packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22087" source="BID">22087</ref>
      <ref url="http://www.openbsd.org/errata39.html#icmp6" source="OPENBSD">[3.9] 018: RELIABILITY FIX: January 16, 2007</ref>
      <ref url="http://www.openbsd.org/errata.html#icmp6" source="OPENBSD">[4.0] 008: RELIABILITY FIX: January 16, 2007</ref>
      <ref url="http://securitytracker.com/id?1017518" source="SECTRACK">1017518</ref>
      <ref url="http://www.osvdb.org/32935" source="OSVDB">32935</ref>
      <ref url="http://secunia.com/advisories/23830" source="SECUNIA">23830</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers prev="1" num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0344" published="2007-01-17" name="CVE-2007-0344" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in (1) _invitedToRoom: and (2) _invitedToDirectChat: in Colloquy 2.1 and earlier allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in the channel name of an INVITE request, related to the implementation of AlertSheet and AlertPanel in Apple AppKit.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22086" source="BID" patch="1">22086</ref>
      <ref url="http://secunia.com/advisories/23801" source="SECUNIA" patch="1" adv="1">23801</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0238" source="VUPEN" adv="1">ADV-2007-0238</ref>
      <ref url="http://www.osvdb.org/32688" source="OSVDB">32688</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-16-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-16-01-2007.html</ref>
      <ref url="http://milw0rm.com/exploits/3139" source="MILW0RM">3139</ref>
    </refs>
    <vuln_soft>
      <prod vendor="colloquy" name="colloquy">
        <vers prev="1" num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0345" published="2007-01-17" name="CVE-2007-0345" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The (1) Activity Monitor.app/Contents/Resources/pmTool, (2) Keychain Access.app/Contents/Resources/kcproxy, and (3) ODBC Administrator.app/Contents/Resources/iodbcadmintool programs in /Applications/Utilities/ in Mac OS X 10.4.8 have weak permissions (writable by admin group), which allows local admin users to gain root privileges by modifying a program and then performing permissions repair via diskutil.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://projects.info-pull.com/moab/MOAB-15-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-15-01-2007.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31530" source="XF">macosx-applications-privilege-escalation(31530)</ref>
      <ref url="http://www.osvdb.org/32702" source="OSVDB">32702</ref>
      <ref url="http://www.osvdb.org/32701" source="OSVDB">32701</ref>
      <ref url="http://www.osvdb.org/32700" source="OSVDB">32700</ref>
      <ref url="http://milw0rm.com/exploits/3136" source="MILW0RM">3136</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0346" published="2007-01-17" name="CVE-2007-0346" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in SmE FileMailer 1.21 allows remote attackers to execute arbitrary SQL commands via the us parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0221" source="VUPEN">ADV-2007-0221</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001244.html" source="VIM">20070117 Source VERIFY of SMe FileMailer 1.21 SQL injection</ref>
      <ref url="http://osvdb.org/32832" source="OSVDB">32832</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31533" source="XF">smefilemailer-login-sql-injection(31533)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sme" name="filemailer">
        <vers num="1.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0347" published="2007-01-29" name="CVE-2007-0347" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authenticated users to execute limited SQL injection attacks and cause a denial of service (database error) via a ' character in certain messages, tickets, or Wiki entries.</descript>
      <descript source="nvd">The DoS vulnerability exists because the is_eow() function in "format.c" does NOT just check the FIRST character of the supplied string for an End-Of-Word terminating character, but instead iterates over string and this way can skip a single embedded quotation mark. The is_repository_file() function then in turn assumes that the filename string can never contain a single quotation mark and traps into a SQL escaping problem.</descript>
    </desc>
    <impacts>
      <impact source="nvd">An SQL injection via this technique is somewhat limited as is_eow() bails on whitespace. So while one _can_ do an SQL injection, one is limited to SQL queries containing only characters which get past the function isspace(3). This effectively limits attacks to SQL commands like "VACUUM".</impact>
    </impacts>
    <sols>
      <sol source="nvd">Successful remote unauthenticated exploit requires that CVSTrac is explicitly configured to allow anonymous users to add tickets (it is not by default).</sol>
    </sols>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458455/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20070129 CVSTrac 2.0.0 Denial of Service (DoS) vulnerability</ref>
      <ref url="http://www.cvstrac.org/cvstrac/tktview?tn=683" source="MISC" patch="1" adv="1">http://www.cvstrac.org/cvstrac/tktview?tn=683</ref>
      <ref url="http://www.cvstrac.org/cvstrac/chngview?cn=850" source="CONFIRM" patch="1" adv="1">http://www.cvstrac.org/cvstrac/chngview?cn=850</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/052058.html" source="FULLDISC" patch="1" adv="1">20070129 CVSTrac 2.0.0 Denial of Service (DoS) vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0398" source="VUPEN">ADV-2007-0398</ref>
      <ref url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.008.html" source="OPENPKG" adv="1">OpenPKG-SA-2007.008</ref>
      <ref url="http://osvdb.org/31935" source="OSVDB">31935</ref>
      <ref url="http://www.securityfocus.com/bid/22296" source="BID">22296</ref>
      <ref url="http://securityreason.com/securityalert/2192" source="SREASON">2192</ref>
      <ref url="http://secunia.com/advisories/23940" source="SECUNIA">23940</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvstrac" name="cvstrac">
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers prev="1" num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0348" published="2007-03-21" name="CVE-2007-0348" modified="2011-08-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio CinePlayer 3.2, (3) WinDVD 7.0.27.172, and possibly other products, allows remote attackers to execute arbitrary code via a long ApplicationType property.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/922969" source="CERT-VN">VU#922969</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33186" source="XF">interactual-iasysteminfo-bo(33186)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1043" source="VUPEN" adv="1">ADV-2007-1043</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1042" source="VUPEN" adv="1">ADV-2007-1042</ref>
      <ref url="http://www.securityfocus.com/bid/23071" source="BID">23071</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463405/100/0/threaded" source="BUGTRAQ">20070321 Secunia Research: InterActual Player / CinePlayer IASystemInfo.dllActiveX Control Buffer Overflow</ref>
      <ref url="http://secunia.com/secunia_research/2007-37/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-37/advisory/</ref>
      <ref url="http://secunia.com/advisories/24556" source="SECUNIA" adv="1">24556</ref>
      <ref url="http://secunia.com/advisories/23075" source="SECUNIA" adv="1">23075</ref>
      <ref url="http://secunia.com/advisories/23032" source="SECUNIA" adv="1">23032</ref>
      <ref url="http://osvdb.org/34315" source="OSVDB">34315</ref>
      <ref url="http://osvdb.org/34314" source="OSVDB">34314</ref>
    </refs>
    <vuln_soft>
      <prod vendor="interactual_technologies" name="interactual_player">
        <vers num="2.60.12.0717"/>
      </prod>
      <prod vendor="intervideo" name="windvd">
        <vers num="7.0.27.172"/>
      </prod>
      <prod vendor="roxio" name="cineplayer">
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0349" published="2007-01-18" name="CVE-2007-0349" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in upgrade.php in nicecoder.com INDEXU 5.x allows remote attackers to include arbitrary local files via a .. (dot dot) in the gateway parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457079/100/0/threaded" source="BUGTRAQ">20070116 vulnerability script indexu all versions</ref>
      <ref url="http://osvdb.org/45533" source="OSVDB">45533</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31539" source="XF">indexu-upgrade-file-include(31539)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nicecoder" name="indexu">
        <vers prev="1" num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0350" published="2007-01-18" name="CVE-2007-0350" modified="2011-09-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in (a) index.php and (b) dl.php in SmE FileMailer 1.21 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ps, (2) us, (3) f, or (4) code parameter.  NOTE: the us vector in index.php is already covered by CVE-2007-0346.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31533" source="XF">smefilemailer-login-sql-injection(31533)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0221" source="VUPEN" adv="1">ADV-2007-0221</ref>
      <ref url="http://osvdb.org/32833" source="OSVDB">32833</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-January/001244.html" source="VIM">20070117 Source VERIFY of SMe FileMailer 1.21 SQL injection</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2007-01/0395.html" source="BUGTRAQ">20070116 [x0n3-h4ck] SmE FileMailer 1.21 Remote Sql Injextion Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sme" name="filemailer">
        <vers prev="1" num="1.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0351" published="2007-01-18" name="CVE-2007-0351" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Microsoft Windows XP and Windows Server 2003 do not properly handle user logoff, which might allow local users to gain the privileges of a previous system user, possibly related to user profile unload failure. NOTE: it is not clear whether this is an issue in Windows itself, or an interaction with another product.  The issue might involve ZoneAlarm not being able to terminate processes when it cannot prompt the user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
      <race/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459838/100/0/threaded" source="BUGTRAQ">20070211 Windows logoff bug solution possibly.</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457807/100/200/threaded" source="BUGTRAQ">20070123 Re: Windows logoff bug possible security vulnerability and exploit.</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457340/100/0/threaded" source="BUGTRAQ">20070118 Re: Windows logoff bug possible security vulnerability and exploit.</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457217/100/0/threaded" source="BUGTRAQ">20070117 Re: Windows logoff bug possible security vulnerability and exploit.</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457167/100/0/threaded" source="BUGTRAQ">20070117 Windows logoff bug possible security vulnerability and exploit.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zonelabs" name="zonealarm">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0352" published="2007-01-18" name="CVE-2007-0352" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a crafted .cnt file composed of lines that begin with an integer followed by a space and a long string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457210/100/0/threaded" source="BUGTRAQ">20070117 Microsoft Help Workshop .CNT contents files buffer overflow vulnerability</ref>
      <ref url="http://www.anspi.pl/~porkythepig/visualization/cnt-expl1.cpp" source="MISC">http://www.anspi.pl/~porkythepig/visualization/cnt-expl1.cpp</ref>
      <ref url="http://osvdb.org/31898" source="OSVDB">31898</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31555" source="XF">ms-help-workshop-cnt-bo(31555)</ref>
      <ref url="http://www.securityfocus.com/bid/22100" source="BID">22100</ref>
      <ref url="http://securitytracker.com/id?1017530" source="SECTRACK">1017530</ref>
      <ref url="http://securityreason.com/securityalert/2156" source="SREASON">2156</ref>
      <ref url="http://secunia.com/advisories/23862" source="SECUNIA">23862</ref>
      <ref url="http://milw0rm.com/exploits/3149" source="MILW0RM">3149</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="html_help_workshop">
        <vers num="4.02.0002"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0353" published="2007-01-18" name="CVE-2007-0353" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in (1) index.php and (2) login.php in myBloggie 2.1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22097" source="BID">22097</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457206/100/0/threaded" source="BUGTRAQ">20070117 [x0n3-h4ck] myBloggie 2.1.5 XSS exploit</ref>
      <ref url="http://osvdb.org/32930" source="OSVDB">32930</ref>
      <ref url="http://osvdb.org/32929" source="OSVDB">32929</ref>
      <ref url="http://mywebland.com/forums/showtopic.php?t=1224" source="MISC">http://mywebland.com/forums/showtopic.php?t=1224</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0338.html" source="FULLDISC">20070117 [x0n3-h4ck] myBloggie 2.1.5 XSS exploit</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31554" source="XF">mybloggie-indexlogin-xss(31554)</ref>
      <ref url="http://securitytracker.com/id?1017531" source="SECTRACK">1017531</ref>
      <ref url="http://securityreason.com/securityalert/2155" source="SREASON">2155</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mywebland" name="mybloggie">
        <vers num="2.1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0354" published="2007-01-18" name="CVE-2007-0354" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in email.php in MGB OpenSource Guestbook 0.5.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0232" source="VUPEN">ADV-2007-0232</ref>
      <ref url="http://www.tv-kritik.net/mgb/index.php" source="CONFIRM">http://www.tv-kritik.net/mgb/index.php</ref>
      <ref url="http://www.securityfocus.com/bid/22094" source="BID">22094</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001246.html" source="VIM">20070118 vendor ACK for MGB Guestbook issue</ref>
      <ref url="http://osvdb.org/31612" source="OSVDB">31612</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31551" source="XF">mgb-email-sql-injection(31551)</ref>
      <ref url="http://secunia.com/advisories/23825" source="SECUNIA">23825</ref>
      <ref url="http://milw0rm.com/exploits/3141" source="MILW0RM">3141</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mgb" name="opensource_guestbook">
        <vers prev="1" num="0.5.4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0355" published="2007-01-18" name="CVE-2007-0355" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, including 10.4.8, allows local users, and possibly remote attackers, to gain privileges and possibly execute arbitrary code via a registration request with an invalid attr-list field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-043B.html" source="CERT">TA08-043B</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31562" source="XF">macos-slpd-bo(31562)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0239" source="VUPEN">ADV-2007-0239</ref>
      <ref url="http://www.securityfocus.com/bid/22101" source="BID">22101</ref>
      <ref url="http://www.osvdb.org/32693" source="OSVDB">32693</ref>
      <ref url="http://securitytracker.com/id?1017533" source="SECTRACK">1017533</ref>
      <ref url="http://secunia.com/advisories/23796" source="SECUNIA" adv="1">23796</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-17-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-17-01-2007.html</ref>
      <ref url="http://milw0rm.com/exploits/3151" source="MILW0RM">3151</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html" source="APPLE">APPLE-SA-2008-02-11</ref>
      <ref url="http://securitytracker.com/id?1019359" source="SECTRACK">1019359</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307430" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307430</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="minimal_slp_service_agent">
        <vers num="10.4.11"/>
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0356" published="2007-01-18" name="CVE-2007-0356" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Common Controls Replacement Project (CCRP) FolderTreeview (FTV) ActiveX control (ccrpftv6.ocx) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long CCRP.RootFolder property value.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22092" source="BID">22092</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31549" source="XF">ie-ccrp-dos(31549)</ref>
      <ref url="http://milw0rm.com/exploits/3142" source="MILW0RM">3142</ref>
    </refs>
    <vuln_soft>
      <prod vendor="common_controls_replacement_project" name="foldertreeview_activex_control">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="ie">
        <vers num="7.0" edition=""/>
        <vers num="7.0" edition=":vista"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0357" published="2007-01-18" name="CVE-2007-0357" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the AVM IGD CTRL Service in Fritz!DSL 02.02.29 allows remote attackers to read arbitrary files via ..%5C (URL-encoded dot dot backslash) sequences in a URI requested from the AR7 webserver.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0236" source="VUPEN">ADV-2007-0236</ref>
      <ref url="http://www.securityfocus.com/bid/22093" source="BID">22093</ref>
      <ref url="http://osvdb.org/32866" source="OSVDB">32866</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051844.html" source="FULLDISC">20070117 Flaw in AVM UPNP service for windows</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31556" source="XF">fritz-avm-directory-traversal(31556)</ref>
      <ref url="http://securityreason.com/securityalert/2159" source="SREASON">2159</ref>
      <ref url="http://secunia.com/advisories/23774" source="SECUNIA">23774</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fritzdsl" name="fritzdsl">
        <vers num="02.02.29"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0358" published="2007-01-18" name="CVE-2007-0358" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the FTP server implementation in HP Jetdirect firmware x.20.nn through x.24.nn allows remote attackers to cause a denial of service via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23802" source="SECUNIA" patch="1" adv="1">23802</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0233" source="VUPEN">ADV-2007-0233</ref>
      <ref url="http://osvdb.org/32867" source="OSVDB">32867</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00838612" source="HP">HPSBPI02185</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00838612" source="HP">HPSBPI02185</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31589" source="XF">hp-jetdirect-unspecified-dos(31589)</ref>
      <ref url="http://www.securityfocus.com/bid/22105" source="BID">22105</ref>
      <ref url="http://securitytracker.com/id?1017532" source="SECTRACK">1017532</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="jetdirect_firmware">
        <vers num="x.20.nn"/>
        <vers num="x.21.nn"/>
        <vers num="x.22.nn"/>
        <vers num="x.23.nn"/>
        <vers num="x.24.nn"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0359" published="2007-01-18" name="CVE-2007-0359" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in frontpage.php in Uberghey CMS 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the setup_folder parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0230" source="VUPEN">ADV-2007-0230</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001247.html" source="VIM">20070118 source verify: Uberghey CMS 0.3.1 RFI</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31553" source="XF">uberghey-frontpage-file-include(31553)</ref>
      <ref url="http://www.securityfocus.com/bid/22098" source="BID">22098</ref>
      <ref url="http://milw0rm.com/exploits/3147" source="MILW0RM">3147</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uberghey" name="cms">
        <vers num="0.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0360" published="2007-01-18" name="CVE-2007-0360" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in lang/index.php in Oreon 1.2.3 RC4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0229" source="VUPEN">ADV-2007-0229</ref>
      <ref url="http://osvdb.org/33711" source="OSVDB">33711</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31568" source="XF">oreon-index-file-include(31568)</ref>
      <ref url="http://www.securityfocus.com/bid/22107" source="BID">22107</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459811/100/0/threaded" source="BUGTRAQ">20070211 Oreon1.2.x Series Exploit Coded</ref>
      <ref url="http://milw0rm.com/exploits/3150" source="MILW0RM">3150</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oreon_project" name="oreon">
        <vers prev="1" num="1.2.3_rc4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0361" published="2007-01-18" name="CVE-2007-0361" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in mep/frame.php in PHPMyphorum 1.5a allows remote attackers to execute arbitrary PHP code via a URL in the chem parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0231" source="VUPEN">ADV-2007-0231</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31552" source="XF">phpmyphorum-frame-file-include(31552)</ref>
      <ref url="http://www.securityfocus.com/bid/22099" source="BID">22099</ref>
      <ref url="http://milw0rm.com/exploits/3145" source="MILW0RM">3145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comscripts" name="phpmyphorum">
        <vers num="1.5a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0362" published="2007-01-18" name="CVE-2007-0362" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the RSS feed component in FreshReader before 1.0.07010600 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to tag attributes.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0241" source="VUPEN">ADV-2007-0241</ref>
      <ref url="http://secunia.com/advisories/23806" source="SECUNIA" adv="1">23806</ref>
      <ref url="http://osvdb.org/32923" source="OSVDB">32923</ref>
      <ref url="http://manual.freshreader.com/archives/2007/01/20070118_javasc.html" source="CONFIRM">http://manual.freshreader.com/archives/2007/01/20070118_javasc.html</ref>
      <ref url="http://jvn.jp/jp/JVN%2395249468/index.html" source="JVN">JVN#95249468</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31566" source="XF">freshreader-rssfeed-xss(31566)</ref>
      <ref url="http://www.securityfocus.com/bid/22106" source="BID">22106</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freshreader" name="freshreader">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0363" published="2007-01-18" name="CVE-2007-0363" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in admin-search.php in (1) Openads for PostgreSQL (aka phpPgAds) before 2.0.10 and (2) Openads (aka phpAdsNew) before 2.0.10 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=36679&amp;release_id=479426" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=36679&amp;release_id=479426</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=11386&amp;release_id=479424" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=11386&amp;release_id=479424</ref>
      <ref url="http://secunia.com/advisories/23720" source="SECUNIA" patch="1" adv="1">23720</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0240" source="VUPEN">ADV-2007-0240</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31570" source="XF">openads-unspecified-xss(31570)</ref>
      <ref url="http://www.securityfocus.com/bid/22124" source="BID">22124</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openads" name="openads">
        <vers num="2.0.8_pr1" edition=""/>
        <vers num="2.0.8_pr1" edition=":postgresql"/>
        <vers num="2.0.9_pr1" edition=""/>
        <vers num="2.0.9_pr1" edition=":postgresql"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0364" published="2007-01-19" name="CVE-2007-0364" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in nicecoder.com INDEXU 5.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) error_msg parameter to (a) suggest_category.php; the (2) u parameter to (b) user_detail.php; the (3) friend_name, (4) friend_email, (5) error_msg, (6) my_name, (7) my_email, and (8) id parameters to (c) tell_friend.php; the (9) error_msg, (10) email, (11) name, and (12) subject parameters to (d) sendmail.php; the (13) email, (14) error_msg, and (15) username parameters to (e) send_pwd.php; the (16) keyword parameter to (f) search.php; the (17) error_msg, (18) username, (19) password, (20) password2, and (21) email parameters to (g) register.php; the (22) url, (23) contact_name, and (24) email parameters to (h) power_search.php; the (25) path and (26) total parameters to (i) new.php; the (27) query parameter to (j) modify.php; the (28) error_msg parameter to (k) login.php; the (29) error_msg and (30) email parameters to (l) mailing_list.php; the (31) gateway parameter to (m) upgrade.php; and another unspecified vector.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31538" source="XF">indexu-multiple-scripts-xss(31538)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0222" source="VUPEN" adv="1">ADV-2007-0222</ref>
      <ref url="http://www.securityfocus.com/bid/22084" source="BID">22084</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457079/100/0/threaded" source="BUGTRAQ">20070116 vulnerability script indexu all versions</ref>
      <ref url="http://www.osvdb.org/32851" source="OSVDB">32851</ref>
      <ref url="http://www.osvdb.org/32850" source="OSVDB">32850</ref>
      <ref url="http://www.osvdb.org/32849" source="OSVDB">32849</ref>
      <ref url="http://www.osvdb.org/32848" source="OSVDB">32848</ref>
      <ref url="http://www.osvdb.org/32847" source="OSVDB">32847</ref>
      <ref url="http://www.osvdb.org/32846" source="OSVDB">32846</ref>
      <ref url="http://www.osvdb.org/32845" source="OSVDB">32845</ref>
      <ref url="http://www.osvdb.org/32844" source="OSVDB">32844</ref>
      <ref url="http://www.osvdb.org/32843" source="OSVDB">32843</ref>
      <ref url="http://www.osvdb.org/32842" source="OSVDB">32842</ref>
      <ref url="http://www.osvdb.org/32841" source="OSVDB">32841</ref>
      <ref url="http://www.osvdb.org/32840" source="OSVDB">32840</ref>
      <ref url="http://www.osvdb.org/32838" source="OSVDB">32838</ref>
      <ref url="http://secunia.com/advisories/23764" source="SECUNIA" adv="1">23764</ref>
      <ref url="http://osvdb.org/32839" source="OSVDB">32839</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nicecoder" name="indexu">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers prev="1" num="5.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0365" published="2007-01-19" name="CVE-2007-0365" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in All In One Control Panel (AIOCP) 1.3.009 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: this is probably a different vulnerability than CVE-2006-5830.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31486" source="XF" patch="1">aiocp-unspecified-xss(31486)</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=478370" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=478370</ref>
      <ref url="http://secunia.com/advisories/23732" source="SECUNIA" patch="1" adv="1">23732</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0189" source="VUPEN">ADV-2007-0189</ref>
      <ref url="http://osvdb.org/32808" source="OSVDB">32808</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nicola_asuni" name="all_in_one_control_panel">
        <vers num="1.3.000"/>
        <vers num="1.3.001"/>
        <vers num="1.3.002"/>
        <vers num="1.3.003"/>
        <vers num="1.3.004"/>
        <vers num="1.3.005"/>
        <vers num="1.3.006"/>
        <vers num="1.3.007"/>
        <vers num="1.3.008"/>
        <vers prev="1" num="1.3.009"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0366" published="2007-01-19" name="CVE-2007-0366" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Rumpus 5.1 and earlier allows local users to gain privileges via a modified PATH that points to a malicious ipfw program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31597" source="XF">rumpus-path-privilege-escalation(31597)</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-18-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-18-01-2007.html</ref>
      <ref url="http://osvdb.org/32690" source="OSVDB">32690</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31597" source="XF">rumpus-path-privilege-escalation(31597)</ref>
      <ref url="http://secunia.com/advisories/23842" source="SECUNIA">23842</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxum_development_corporation" name="rumpus_ftp_server">
        <vers prev="1" num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0367" published="2007-01-19" name="CVE-2007-0367" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Rumpus 5.1 and earlier has weak permissions for certain files and directories under /usr/local/Rumpus, including the configuration file, which allows local users to have an unknown impact by creating, modifying, or deleting files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://projects.info-pull.com/moab/MOAB-18-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-18-01-2007.html</ref>
      <ref url="http://osvdb.org/32691" source="OSVDB">32691</ref>
      <ref url="http://secunia.com/advisories/23842" source="SECUNIA">23842</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxum_development_corporation" name="rumpus_ftp_server">
        <vers prev="1" num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0368" published="2007-01-19" name="CVE-2007-0368" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in mbse-bbs 0.70 and earlier allows local users to execute arbitrary code via a long string in the MBSE_ROOT environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22112" source="BID">22112</ref>
      <ref url="http://www.mbse.eu/mbse/mbsebbs/index.html" source="MISC">http://www.mbse.eu/mbse/mbsebbs/index.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31639" source="XF">mbsebbs-mbuseradd-bo(31639)</ref>
      <ref url="http://milw0rm.com/exploits/3154" source="MILW0RM">3154</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051859.html" source="FULLDISC">20070118 mbsebbs 0.70.0 &amp; below local root exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michiel_broek" name="mbse-bbs">
        <vers num="0.33.17"/>
        <vers num="0.33.18"/>
        <vers num="0.33.19"/>
        <vers num="0.33.20"/>
        <vers num="0.35.7"/>
        <vers num="0.36"/>
        <vers num="0.38"/>
        <vers num="0.60"/>
        <vers num="0.70"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0369" published="2007-01-19" name="CVE-2007-0369" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in phpBP RC3 (2.204) and earlier allows remote attackers to execute arbitrary SQL commands via the comment forum.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://osvdb.org/34763" source="OSVDB">34763</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31622" source="XF">phpbp-comment-sql-injection(31622)</ref>
      <ref url="http://milw0rm.com/exploits/3153" source="MILW0RM">3153</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbp" name="phpbp">
        <vers num="rc3_2.204"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0370" published="2007-01-19" name="CVE-2007-0370" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in index.php in phpBP RC3 (2.204) and earlier allows remote administrators to inject arbitrary PHP code into an upload/banners/ file via a banners add operation that uploads the PHP code through an image_form parameter specifying a multiple-extension filename such as .jpg.vil.gif.php, which is stored in upload/banners/ under a different name, and executable via a direct request.  NOTE: a separate SQL injection issue could be leveraged to make this vulnerability reachable by remote unauthenticated attackers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://osvdb.org/34762" source="OSVDB">34762</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31619" source="XF">phpbp-banner-file-upload(31619)</ref>
      <ref url="http://milw0rm.com/exploits/3153" source="MILW0RM">3153</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbp" name="phpbp">
        <vers num="rc3_2.204"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0371" published="2007-01-19" name="CVE-2007-0371" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long CCRP_BDc.SelectedFolder property value.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22110" source="BID" adv="1">22110</ref>
      <ref url="http://osvdb.org/34647" source="OSVDB">34647</ref>
      <ref url="http://milw0rm.com/exploits/3155" source="MILW0RM">3155</ref>
    </refs>
    <vuln_soft>
      <prod vendor="common_controls_replacement_project" name="browsedialog_server">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0372" published="2007-01-19" name="CVE-2007-0372" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Francisco Burzi PHP-Nuke 7.9 allow remote attackers to execute arbitrary SQL commands via (1) the active parameter in admin/modules/modules.php; the (2) ad_class, (3) imageurl, (4) clickurl, (5) ad_code, or (6) position parameter in modules/Advertising/admin/index.php; or unspecified vectors in the (7) advertising, (8) weblinks, or (9) reviews section.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22116" source="BID" adv="1">22116</ref>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/33702" source="OSVDB">33702</ref>
      <ref url="http://osvdb.org/33701" source="OSVDB">33701</ref>
      <ref url="http://osvdb.org/33700" source="OSVDB">33700</ref>
      <ref url="http://osvdb.org/33699" source="OSVDB">33699</ref>
      <ref url="http://osvdb.org/33698" source="OSVDB">33698</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC">20070118 The vulnerabilities festival !</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459174/100/0/threaded" source="BUGTRAQ">20070204 Sql injection bugs in PHP-Nuke</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="7.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0373" published="2007-01-19" name="CVE-2007-0373" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Joomla! 1.5.0 Beta allow remote attackers to execute arbitrary SQL commands via (1) the searchword parameter in certain files; the where parameter in (2) plugins/search/content.php or (3) plugins/search/weblinks.php; the text parameter in (4) plugins/search/contacts.php, (5) plugins/search/categories.php, or (6) plugins/search/sections.php; or (7) the email parameter in database/table/user.php, which is not properly handled by the check function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22122" source="BID" adv="1">22122</ref>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/32533" source="OSVDB">32533</ref>
      <ref url="http://osvdb.org/32532" source="OSVDB">32532</ref>
      <ref url="http://osvdb.org/32531" source="OSVDB">32531</ref>
      <ref url="http://osvdb.org/32530" source="OSVDB">32530</ref>
      <ref url="http://osvdb.org/32529" source="OSVDB">32529</ref>
      <ref url="http://osvdb.org/32528" source="OSVDB">32528</ref>
      <ref url="http://osvdb.org/32527" source="OSVDB">32527</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC">20070118 The vulnerabilities festival !</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459203/100/0/threaded" source="BUGTRAQ">20070204 Sql injection bugs in Joomla and Mambo</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="joomla">
        <vers num="1.5.0_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0374" published="2007-01-19" name="CVE-2007-0374" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in (1) Joomla! 1.0.11 and 1.5 Beta, and (2) Mambo 4.6.1, allows remote attackers to execute arbitrary SQL commands via the id parameter when cancelling content editing.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC" patch="1" adv="1">20070118 The vulnerabilities festival !</ref>
      <ref url="http://www.securityfocus.com/bid/19734" source="BID" adv="1">19734</ref>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC" adv="1">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/32520" source="OSVDB">32520</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459203/100/0/threaded" source="BUGTRAQ">20070204 Sql injection bugs in Joomla and Mambo</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="joomla">
        <vers num="1.0.11"/>
        <vers num="1.5.0_beta"/>
      </prod>
      <prod vendor="mambo" name="mambo">
        <vers num="4.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0375" published="2007-01-19" name="CVE-2007-0375" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Joomla! 1.5.0 Beta allows remote attackers to obtain sensitive information via a direct request for (1) plugins/user/example.php; (2) gmail.php, (3) example.php, or (4) ldap.php in plugins/authentication/; (5) modules/mod_mainmenu/menu.php; or other unspecified PHP scripts, which reveals the path in various error messages, related to a jimport function call at the beginning of each script.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC" adv="1">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/32526" source="OSVDB">32526</ref>
      <ref url="http://osvdb.org/32525" source="OSVDB">32525</ref>
      <ref url="http://osvdb.org/32524" source="OSVDB">32524</ref>
      <ref url="http://osvdb.org/32523" source="OSVDB">32523</ref>
      <ref url="http://osvdb.org/32522" source="OSVDB">32522</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC" adv="1">20070118 The vulnerabilities festival !</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459203/100/0/threaded" source="BUGTRAQ">20070204 Sql injection bugs in Joomla and Mambo</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="joomla">
        <vers num="1.5.0_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0376" published="2007-01-19" name="CVE-2007-0376" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Virtuemart 1.0.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22123" source="BID" adv="1">22123</ref>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC" adv="1">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://virtuemart.svn.sourceforge.net/viewvc/%2Acheckout%2A/virtuemart/branches/virtuemart-1_0_0/virtuemart/CHANGELOG.php?revision=607" source="MISC">http://virtuemart.svn.sourceforge.net/viewvc/*checkout*/virtuemart/branches/virtuemart-1_0_0/virtuemart/CHANGELOG.php?revision=607</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC" adv="1">20070118 The vulnerabilities festival !</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459195/100/0/threaded" source="BUGTRAQ">20070204 Sql injection bugs in Virtuemart and Letterman</ref>
      <ref url="http://secunia.com/advisories/24058" source="SECUNIA">24058</ref>
    </refs>
    <vuln_soft>
      <prod vendor="virtuemart" name="virtuemart">
        <vers num="1.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0377" published="2007-01-19" name="CVE-2007-0377" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Xoops 2.0.16 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in kernel/group.php in core, (2) the lid parameter in class/table_broken.php in the Weblinks module, and other unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC" adv="1">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/33685" source="OSVDB">33685</ref>
      <ref url="http://osvdb.org/33684" source="OSVDB">33684</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC" adv="1">20070118 The vulnerabilities festival !</ref>
      <ref url="http://www.securityfocus.com/bid/22399" source="BID">22399</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459150/100/0/threaded" source="BUGTRAQ">20070204 Sql injection bugs in Xoops 2.0.16 + Weblinks module</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xoops" name="xoops">
        <vers num="2.0.16"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0378" published="2007-01-19" name="CVE-2007-0378" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in DocMan 1.3 RC2 allow attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC" adv="1">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/34650" source="OSVDB">34650</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC" adv="1">20070118 The vulnerabilities festival !</ref>
    </refs>
    <vuln_soft>
      <prod vendor="docman" name="docman">
        <vers num="1.3_rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0379" published="2007-01-19" name="CVE-2007-0379" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in DocMan 1.3 RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC" adv="1">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/34651" source="OSVDB">34651</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC" adv="1">20070118 The vulnerabilities festival !</ref>
    </refs>
    <vuln_soft>
      <prod vendor="docman" name="docman">
        <vers num="1.3_rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0380" published="2007-01-19" name="CVE-2007-0380" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">DocMan 1.3 RC2 allows remote attackers to obtain sensitive information (the full path) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC" adv="1">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/34652" source="OSVDB">34652</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC" adv="1">20070118 The vulnerabilities festival !</ref>
    </refs>
    <vuln_soft>
      <prod vendor="docman" name="docman">
        <vers num="1.3_rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0381" published="2007-01-19" name="CVE-2007-0381" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in ATutor 1.5.3.2 allow remote attackers to execute arbitrary SQL commands via unspecified parameters.  NOTE: CVE analysis suggests that the vendor fixed these issues.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.atutor.ca/atutor/mantis/changelog_page.php" source="MISC" patch="1" adv="1">http://www.atutor.ca/atutor/mantis/changelog_page.php</ref>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC" adv="1">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/34660" source="OSVDB">34660</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC" adv="1">20070118 The vulnerabilities festival !</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adaptive_technology_resource_centre" name="atutor">
        <vers num="1.5.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0382" published="2007-01-19" name="CVE-2007-0382" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in letterman.class.php in the Letterman 1.2.3 (com_letterman) component for Joomla! before 1.0.12 allow remote attackers to execute arbitrary SQL commands via the id parameter, related to the (1) lm_sendMail, (2) saveNewsletter, and (3) cancelNewsletter functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22117" source="BID" adv="1">22117</ref>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC" adv="1">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/33688" source="OSVDB">33688</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC" adv="1">20070118 The vulnerabilities festival !</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459195/100/0/threaded" source="BUGTRAQ">20070204 Sql injection bugs in Virtuemart and Letterman</ref>
    </refs>
    <vuln_soft>
      <prod vendor="letterman" name="letterman">
        <vers num="1.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0383" published="2007-01-19" name="CVE-2007-0383" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">** DISPUTED **  WDaemon 9.5.4 allows remote attackers to access the /WorldClient.dll URI on TCP port 3000, which has unknown impact.  NOTE: The researcher reports that the vendor response was "this is not a security bug."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC" adv="1">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/34661" source="OSVDB">34661</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC" adv="1">20070118 The vulnerabilities festival !</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wdaemon" name="wdaemon">
        <vers num="7.2.0"/>
        <vers num="9.0.4"/>
        <vers num="9.5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0384" published="2007-01-19" name="CVE-2007-0384" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in preview in the reviews section in PostNuke 0.764 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22119" source="BID">22119</ref>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/35473" source="OSVDB">35473</ref>
      <ref url="http://noc.postnuke.com/plugins/scmsvn/viewcvs.php/trunk/Historic/PostNuke7x/html/modules/?root=postnuke" source="CONFIRM">http://noc.postnuke.com/plugins/scmsvn/viewcvs.php/trunk/Historic/PostNuke7x/html/modules/?root=postnuke</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC">20070118 The vulnerabilities festival !</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.764"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0385" published="2007-01-19" name="CVE-2007-0385" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The faq section in PostNuke 0.764 allows remote attackers to obtain sensitive information (the full path) via "unvalidated output" in FAQ/index.php, possibly involving an undefined id_cat variable.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/35472" source="OSVDB">35472</ref>
      <ref url="http://noc.postnuke.com/plugins/scmsvn/viewcvs.php/trunk/Historic/PostNuke7x/html/modules/FAQ/index.php?root=postnuke&amp;r1=20350&amp;r2=20911" source="CONFIRM">http://noc.postnuke.com/plugins/scmsvn/viewcvs.php/trunk/Historic/PostNuke7x/html/modules/FAQ/index.php?root=postnuke&amp;r1=20350&amp;r2=20911</ref>
      <ref url="http://noc.postnuke.com/plugins/scmsvn/viewcvs.php/trunk/Historic/PostNuke7x/html/modules/?root=postnuke" source="CONFIRM">http://noc.postnuke.com/plugins/scmsvn/viewcvs.php/trunk/Historic/PostNuke7x/html/modules/?root=postnuke</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC">20070118 The vulnerabilities festival !</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.764"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0386" published="2007-01-19" name="CVE-2007-0386" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the rating section in PostNuke 0.764 has unknown impact and attack vectors, related to "an interesting bug."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/35471" source="OSVDB">35471</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC">20070118 The vulnerabilities festival !</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.764"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0387" published="2007-01-19" name="CVE-2007-0387" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in models/category.php in the Weblinks component for Joomla! SVN 20070118 (com_weblinks) allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/34792" source="OSVDB">34792</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC">20070118 The vulnerabilities festival !</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459203/100/0/threaded" source="BUGTRAQ">20070204 Sql injection bugs in Joomla and Mambo</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="joomla">
        <vers num="2007-01-18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0388" published="2007-01-19" name="CVE-2007-0388" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the 2.x series, allows remote attackers to execute arbitrary SQL commands via the boardids[1] and other boardids[] parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31550" source="XF">wbb-search-sql-injection(31550)</ref>
      <ref url="http://osvdb.org/33872" source="OSVDB">33872</ref>
      <ref url="http://milw0rm.com/exploits/3144" source="MILW0RM">3144</ref>
      <ref url="http://milw0rm.com/exploits/3143" source="MILW0RM">3143</ref>
    </refs>
    <vuln_soft>
      <prod vendor="woltlab" name="burning_board">
        <vers prev="1" num="1.0.2"/>
        <vers prev="1" num="2.3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0389" published="2007-01-19" name="CVE-2007-0389" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ArsDigita Community System (ACS) 3.4.10 and earlier, and ArsDigita Community Education Solution (ACES) 1.1, allows remote attackers to read arbitrary files via .%252e/ (double-encoded dot dot slash) sequences in the URI.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0286" source="VUPEN">ADV-2007-0286</ref>
      <ref url="http://www.securityfocus.com/bid/22121" source="BID">22121</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457318/100/0/threaded" source="BUGTRAQ">20070118 Directory Traversal in ArsDigita Community System</ref>
      <ref url="http://osvdb.org/33552" source="OSVDB">33552</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31613" source="XF">acs-url-directory-traversal(31613)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arsdigita" name="arsdigita_community_education_solution">
        <vers num="1.1"/>
      </prod>
      <prod vendor="arsdigita" name="arsdigita_community_system">
        <vers prev="1" num="3.4.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0390" published="2007-01-19" name="CVE-2007-0390" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in sabros.us 1.7 allows remote attackers to inject arbitrary web script or HTML via the tag parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22115" source="BID">22115</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457331/100/0/threaded" source="BUGTRAQ">20070118 [x0n3-h4ck] sabros.us 1.7 XSS Exploit</ref>
      <ref url="http://osvdb.org/31602" source="OSVDB">31602</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051868.html" source="FULLDISC">20070118 [x0n3-h4ck] sabros.us 1.7 XSS Exploit</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31600" source="XF">sabros-index-xss(31600)</ref>
      <ref url="http://securityreason.com/securityalert/2170" source="SREASON">2170</ref>
      <ref url="http://secunia.com/advisories/23824" source="SECUNIA">23824</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051868.html" source="FULLDISC">20070118 [x0ne-h4ck] sabros.us 1.7 XSS Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sabros.us" name="sabros.us">
        <vers num="1.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0391" published="2007-01-19" name="CVE-2007-0391" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in the log creation functionality of BitDefender Client Professional Plus 8.02 allows attackers to execute arbitrary code via certain scan job settings.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0253" source="VUPEN">ADV-2007-0253</ref>
      <ref url="http://www.bitdefender.com/KB325-en--Format-string-vulnerability.html" source="CONFIRM">http://www.bitdefender.com/KB325-en--Format-string-vulnerability.html</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051883.html" source="FULLDISC">20070119 Layered Defense Research Advisory: BitDefender Client 8.02 Format String Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31608" source="XF">bitdefender-scanjob-format-string(31608)</ref>
      <ref url="http://www.securityfocus.com/bid/22128" source="BID">22128</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457414/100/0/threaded" source="BUGTRAQ">20070119 Layered Defense Research Advisory: BitDefender Client 8.02 Format String Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bitdefender" name="bitdefender_client">
        <vers num="professional_plus_8.02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0392" published="2007-01-19" name="CVE-2007-0392" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">IBM AIX 5.3 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457315/100/0/threaded" source="BUGTRAQ">20070118 Re: Multiple OS kernel insecure handling of stdio file descriptor</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457279/100/0/threaded" source="BUGTRAQ">20070118 Multiple OS kernel insecure handling of stdio file descriptor</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0393" published="2007-01-19" name="CVE-2007-0393" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Sun Solaris 9 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457315/100/0/threaded" source="BUGTRAQ">20070118 Re: Multiple OS kernel insecure handling of stdio file descriptor</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457279/100/0/threaded" source="BUGTRAQ">20070118 Multiple OS kernel insecure handling of stdio file descriptor</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0394" published="2007-01-19" name="CVE-2007-0394" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">HP HP-UX B11.11 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457315/100/0/threaded" source="BUGTRAQ">20070118 Re: Multiple OS kernel insecure handling of stdio file descriptor</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457279/100/0/threaded" source="BUGTRAQ">20070118 Multiple OS kernel insecure handling of stdio file descriptor</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0395" published="2007-01-19" name="CVE-2007-0395" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in libraries/grab_globals.lib.php in ComVironment 4.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0266" source="VUPEN">ADV-2007-0266</ref>
      <ref url="http://www.securityfocus.com/bid/22108" source="BID">22108</ref>
      <ref url="http://osvdb.org/34621" source="OSVDB">34621</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31564" source="XF">comvironment-grabglobals-file-include(31564)</ref>
      <ref url="http://milw0rm.com/exploits/3152" source="MILW0RM">3152</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comvironment" name="comvironment">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0396" published="2007-01-19" name="CVE-2007-0396" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP-UX B.11.23, when running IPFilter in combination with PHNE_34474, allows remote attackers to cause a denial of service (system crash) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0234" source="VUPEN">ADV-2007-0234</ref>
      <ref url="http://www.securityfocus.com/bid/22103" source="BID">22103</ref>
      <ref url="http://securitytracker.com/id?1017527" source="SECTRACK">1017527</ref>
      <ref url="http://secunia.com/advisories/23800" source="SECUNIA" adv="1">23800</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6104" source="OVAL">oval:org.mitre.oval:def:6104</ref>
      <ref url="http://osvdb.org/32869" source="OSVDB">32869</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00837319" source="HP">HPSBUX02181</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00837319" source="HP">HPSBUX02181</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31565" source="XF">hp-ipfilter-dos(31565)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.23" edition=""/>
        <vers num="11.23" edition=":ia64_64-bit"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0397" published="2007-01-19" name="CVE-2007-0397" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.3 and Adaptive Security Device Manager (ASDM) before 5.2(2.54) do not validate the SSL/TLS certificates or SSH public keys when connecting to devices, which allows remote attackers to spoof those devices to obtain sensitive information or generate incorrect information.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807c517f.shtml" source="CISCO" patch="1">20070118 SSL/TLS Certificate and SSH Public Key Validation Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0245" source="VUPEN">ADV-2007-0245</ref>
      <ref url="http://osvdb.org/32720" source="OSVDB">32720</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31567" source="XF">cisco-csmars-asdm-device-spoofing(31567)</ref>
      <ref url="http://www.securityfocus.com/bid/22111" source="BID">22111</ref>
      <ref url="http://securitytracker.com/id?1017536" source="SECTRACK">1017536</ref>
      <ref url="http://securitytracker.com/id?1017535" source="SECTRACK">1017535</ref>
      <ref url="http://secunia.com/advisories/23836" source="SECUNIA">23836</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_device_manager">
        <vers num="5.2.53"/>
      </prod>
      <prod vendor="cisco" name="security_monitoring_analysis_and_response_system">
        <vers num="4.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0398" published="2007-01-22" name="CVE-2007-0398" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in forum.php3 in Arnaud Guyonne (aka Arnotic) a-forum allow remote attackers to inject arbitrary web script or HTML via the (1) Sujet or (2) Pseudo field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31610" source="XF">aforum-unspecified-xss(31610)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457503/100/0/threaded" source="BUGTRAQ">20070119 a-forum xss</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001249.html" source="VIM">20070122 a-forum xss - who? what? where?</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arnotic" name="a-forum">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0399" published="2007-01-22" name="CVE-2007-0399" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in Simple Machines Forum (SMF) 1.1 RC3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) recipient or (2) BCC field when selecting send in a pm action.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457508/100/0/threaded" source="BUGTRAQ">20070120 SMF "index.php?action=pm" Cross Site-Scripting</ref>
      <ref url="http://osvdb.org/32606" source="OSVDB">32606</ref>
      <ref url="http://aria-security.com/forum/showthread.php?p=128" source="MISC">http://aria-security.com/forum/showthread.php?p=128</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31612" source="XF">smf-pm-xss(31612)</ref>
      <ref url="http://www.securityfocus.com/bid/22143" source="BID">22143</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458904/100/0/threaded" source="BUGTRAQ">20070202 Re: SMF "index.php?action=pm" Cross Site-Scripting</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458194/100/100/threaded" source="BUGTRAQ">20070126 Re: Re: Re: Re: SMF "index.php?action=pm" Cross Site-Scripting</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457761/100/200/threaded" source="BUGTRAQ">20070122 Re: Re: Re: SMF "index.php?action=pm" Cross Site-Scripting</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457627/100/0/threaded" source="BUGTRAQ">20070121 Re: SMF "index.php?action=pm" Cross Site-Scripting</ref>
      <ref url="http://securityreason.com/securityalert/2169" source="SREASON">2169</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simple_machines" name="simple_machines_forum">
        <vers num="1.1_rc3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0400" published="2007-01-22" name="CVE-2007-0400" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in admin/memberlist.php in Easebay Resources Login Manager 3.0 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457505/100/0/threaded" source="BUGTRAQ">20070120 Login Manager Multiple HTML Injections</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31614" source="XF">loginmanager-memberlist-xss(31614)</ref>
      <ref url="http://securityreason.com/securityalert/2167" source="SREASON">2167</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easebay_resources" name="login_manager">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0401" published="2007-01-22" name="CVE-2007-0401" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in admin/memberlist.php in Easebay Resources Login Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the init_row parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457505/100/0/threaded" source="BUGTRAQ">20070120 Login Manager Multiple HTML Injections</ref>
      <ref url="http://securityreason.com/securityalert/2167" source="SREASON">2167</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easebay_resources" name="login_manager">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0402" published="2007-01-22" name="CVE-2007-0402" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in admin/edit_member.php in Easebay Resources Paypal Subscription Manager allows remote attackers to inject arbitrary web script or HTML via the username parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457506/100/0/threaded" source="BUGTRAQ">20070120 Paypal Subscription Manager Multiple HTML Injections</ref>
      <ref url="http://osvdb.org/33559" source="OSVDB">33559</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31618" source="XF">psm-editmember-xss(31618)</ref>
      <ref url="http://securityreason.com/securityalert/2168" source="SREASON">2168</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easebay_resources" name="paypal_subscription_manager">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0403" published="2007-01-22" name="CVE-2007-0403" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in admin/memberlist.php in Easebay Resources Paypal Subscription Manager allows remote attackers to execute arbitrary SQL commands via the keyword parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457506/100/0/threaded" source="BUGTRAQ">20070120 Paypal Subscription Manager Multiple HTML Injections</ref>
      <ref url="http://osvdb.org/36103" source="OSVDB">36103</ref>
      <ref url="http://osvdb.org/33560" source="OSVDB">33560</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31616" source="XF">psm-memberlist-sql-injection(31616)</ref>
      <ref url="http://securityreason.com/securityalert/2168" source="SREASON">2168</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easebay_resources" name="paypal_subscription_manager">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0404" published="2007-01-22" name="CVE-2007-0404" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">bin/compile-messages.py in Django 0.95 does not quote argument strings before invoking the msgfmt program through the os.system function, which allows attackers to execute arbitrary commands via shell metacharacters in a (1) .po or (2) .mo file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23826" source="SECUNIA" patch="1" adv="1">23826</ref>
      <ref url="http://code.djangoproject.com/changeset/3592" source="CONFIRM">http://code.djangoproject.com/changeset/3592</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31627" source="XF">django-po-code-execution(31627)</ref>
      <ref url="http://www.securityfocus.com/bid/22134" source="BID">22134</ref>
    </refs>
    <vuln_soft>
      <prod vendor="django_project" name="django">
        <vers num="0.95"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0405" published="2007-01-22" name="CVE-2007-0405" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">The LazyUser class in the AuthenticationMiddleware for Django 0.95 does not properly cache the user name across requests, which allows remote authenticated users to gain the privileges of a different user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23826" source="SECUNIA" patch="1" adv="1">23826</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31628" source="XF">django-request-session-hijacking(31628)</ref>
      <ref url="http://www.securityfocus.com/bid/22138" source="BID">22138</ref>
      <ref url="http://code.djangoproject.com/changeset/3754" source="CONFIRM">http://code.djangoproject.com/changeset/3754</ref>
    </refs>
    <vuln_soft>
      <prod vendor="django_project" name="django">
        <vers num="0.95"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0406" published="2007-01-22" name="CVE-2007-0406" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in the (1) main function in (a) client.c, and the (2) server_setup and (3) server_client_connect functions in (b) server.c in gxine 0.5.9 and earlier allow local users to cause a denial of service (daemon crash) or gain privileges via a long HOME environment variable.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xinehq.de/index.php/news?show_category_id=1" source="CONFIRM">http://xinehq.de/index.php/news?show_category_id=1</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0259" source="VUPEN">ADV-2007-0259</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=9655&amp;release_id=476891" source="CONFIRM">http://sourceforge.net/project/shownotes.php?group_id=9655&amp;release_id=476891</ref>
      <ref url="http://osvdb.org/38321" source="OSVDB">38321</ref>
      <ref url="http://osvdb.org/38320" source="OSVDB">38320</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31604" source="XF">gxine-serversetup-serverclient-bo(31604)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gxine" name="gxine">
        <vers prev="1" num="0.5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0407" published="2007-01-22" name="CVE-2007-0407" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Operation/User.pm in Plain Black WebGUI before 7.3.5 (beta) allows remote attackers to inject arbitrary web script or HTML via the username parameter during anonymous registration, a different vector than CVE-2007-0308.  NOTE: it is possible that a separate "WikiPage titles" issue was also fixed.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31573" source="XF">webgui-username-xss(31573)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0242" source="VUPEN">ADV-2007-0242</ref>
      <ref url="http://www.securityfocus.com/bid/22114" source="BID">22114</ref>
      <ref url="http://www.plainblack.com/downloads/builds/7.3.5-beta/WebGUI/docs/changelog/7.x.x.txt" source="CONFIRM">http://www.plainblack.com/downloads/builds/7.3.5-beta/WebGUI/docs/changelog/7.x.x.txt</ref>
      <ref url="http://www.plainblack.com/bugs/tracker/security-update-cross-site-scripting-vulnerability" source="CONFIRM">http://www.plainblack.com/bugs/tracker/security-update-cross-site-scripting-vulnerability</ref>
      <ref url="http://secunia.com/advisories/23754" source="SECUNIA" adv="1">23754</ref>
      <ref url="http://osvdb.org/32928" source="OSVDB">32928</ref>
    </refs>
    <vuln_soft>
      <prod vendor="plain_black" name="webgui">
        <vers num="6.3.0"/>
        <vers num="6.4.0"/>
        <vers num="6.5.0"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
        <vers num="6.5.5"/>
        <vers num="6.5.6"/>
        <vers num="6.6.0"/>
        <vers num="6.6.1"/>
        <vers num="6.6.2"/>
        <vers num="6.6.3"/>
        <vers num="6.6.4"/>
        <vers num="6.6.5"/>
        <vers num="6.7.0"/>
        <vers num="6.7.1"/>
        <vers num="6.7.2"/>
        <vers num="6.7.3"/>
        <vers num="6.7.4"/>
        <vers num="6.7.5"/>
        <vers num="6.7.6"/>
        <vers num="6.8.1"/>
        <vers num="6.8.2"/>
        <vers num="6.8.3"/>
        <vers num="6.8.4"/>
        <vers num="6.8.5"/>
        <vers num="6.8.6"/>
        <vers num="7.2.3"/>
        <vers num="7.3.4_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0408" published="2007-01-22" name="CVE-2007-0408" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">BEA Weblogic Server 8.1 through 8.1 SP4 does not properly validate client certificates when reusing cached connections, which allows remote attackers to obtain access via an untrusted X.509 certificate.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/202" source="BEA" patch="1" adv="1">BEA07-135.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017519" source="SECTRACK">1017519</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/38500" source="OSVDB">38500</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers prev="1" num="8.1" edition="sp4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0409" published="2007-01-22" name="CVE-2007-0409" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:P/I:N/A:N)" CVSS_score="1.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="2.7" CVSS_base_score="1.5">
    <desc>
      <descript source="cve">BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP4, and 9.0 initial release does not encrypt passwords stored in the JDBCDataSourceFactory MBean Properties, which allows local administrative users to read the cleartext password.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/203" source="BEA" patch="1" adv="1">BEA07-136.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/38501" source="OSVDB">38501</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers prev="1" num="7.0" edition="sp6"/>
        <vers prev="1" num="8.1" edition="sp4"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0410" published="2007-01-22" name="CVE-2007-0410" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the thread management in BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1, when T3 authentication is used, allows remote attackers to cause a denial of service (thread and system hang) via unspecified "sequences of events."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/204" source="BEA" patch="1" adv="1">BEA07-137.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/38502" source="OSVDB">38502</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers prev="1" num="7.0" edition="sp6"/>
        <vers prev="1" num="8.0_sp5"/>
        <vers num="8.1"/>
        <vers num="9.0"/>
        <vers num="9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0411" published="2007-01-22" name="CVE-2007-0411" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">BEA WebLogic Server 8.1 through 8.1 SP5, 9.0, 9.1, and 9.2 Gold, when WS-Security is used, does not properly validate certificates, which allows remote attackers to conduct a man-in-the-middle (MITM) attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/205" source="BEA" patch="1" adv="1">BEA07-138.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/38503" source="OSVDB">38503</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers prev="1" num="8.1" edition="sp5"/>
        <vers num="9.0"/>
        <vers num="9.1"/>
        <vers num="9.2" edition="ga"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0412" published="2007-01-22" name="CVE-2007-0412" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BEA WebLogic Server 6.1 through 6.1 SP7, 7.0 through 7.0 SP7, and 8.1 through 8.1 SP5 allows remote attackers to read arbitrary files inside the class-path property via .ear or exploded .ear files that use the manifest class-path property to point to utility jar files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/206" source="BEA" patch="1" adv="1">BEA07-139.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/38505" source="OSVDB">38505</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers prev="1" num="6.1" edition="sp7"/>
        <vers prev="1" num="7.0" edition="sp7"/>
        <vers prev="1" num="8.1" edition="sp5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0413" published="2007-01-22" name="CVE-2007-0413" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">BEA WebLogic Server 8.1 through 8.1 SP5 stores cleartext data in a backup of config.xml after offline editing, which allows local users to obtain sensitive information by reading this backup file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/207" source="BEA" patch="1" adv="1">BEA07-140.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA" adv="1">23750</ref>
      <ref url="http://osvdb.org/38504" source="OSVDB">38504</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers prev="1" num="8.1" edition="sp5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0414" published="2007-01-22" name="CVE-2007-0414" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BEA WebLogic Server 6.1 through 6.1 SP7, 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, and 9.0 allows remote attackers to cause a denial of service (server hang) via certain requests that cause muxer threads to block when processing error pages.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/208" source="BEA" patch="1" adv="1">BEA07-141.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/38506" source="OSVDB">38506</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers prev="1" num="6.1" edition="sp7"/>
        <vers prev="1" num="7.0" edition="sp6"/>
        <vers prev="1" num="8.1" edition="sp5"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0415" published="2007-01-22" name="CVE-2007-0415" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BEA WebLogic Server 8.1 through 8.1 SP5 does not properly enforce access control after a dynamic update and dynamic redeployment of an application that is implemented through exploded jars, which allows attackers to bypass intended access restrictions.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/209" source="BEA" patch="1" adv="1">BEA07-142.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/38509" source="OSVDB">38509</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers prev="1" num="8.1" edition="sp5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0416" published="2007-01-22" name="CVE-2007-0416" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The WSEE runtime (WS-Security runtime) in BEA WebLogic Server 9.0 and 9.1 does not verify credentials when decrypting client messages, which allows remote attackers to bypass application security.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/210" source="BEA" patch="1" adv="1">BEA07-143.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/38510" source="OSVDB">38510</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="9.0"/>
        <vers num="9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0417" published="2007-01-22" name="CVE-2007-0417" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">BEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows attackers to execute certain EJB container persistence operations with an administrative identity.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/211" source="BEA" patch="1" adv="1">BEA07-144.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/38511" source="OSVDB">38511</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers prev="1" num="7.0" edition="sp7"/>
        <vers num="8.1" edition="sp5"/>
        <vers num="9.0"/>
        <vers num="9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0418" published="2007-01-22" name="CVE-2007-0418" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">BEA WebLogic Server 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1 does not enforce a security policy that declares permissions for EJB methods that have array parameters, which allows remote attackers to obtain unauthorized access to these methods.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/212" source="BEA" patch="1" adv="1">BEA07-145.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/38512" source="OSVDB">38512</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers prev="1" num="7.0" edition="sp6"/>
        <vers prev="1" num="8.1" edition="sp5"/>
        <vers num="9.0"/>
        <vers num="9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0419" published="2007-01-22" name="CVE-2007-0419" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The BEA WebLogic Server proxy plug-in before June 2006 for the Apache HTTP Server does not properly handle protocol errors, which allows remote attackers to cause a denial of service (server outage).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/213" source="BEA" patch="1" adv="1">BEA07-146.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/38513" source="OSVDB">38513</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0420" published="2007-01-22" name="CVE-2007-0420" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BEA WebLogic Server 9.0, 9.1, and 9.2 Gold allows remote attackers to obtain sensitive information via malformed HTTP requests, which reveal data from previous requests.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/214" source="BEA" patch="1" adv="1">BEA07-147.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/38514" source="OSVDB">38514</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="9.0"/>
        <vers num="9.1"/>
        <vers num="9.2" edition="ga"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0421" published="2007-01-22" name="CVE-2007-0421" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">BEA WebLogic Server 6.1 through 6.1 SP7, and 7.0 through 7.0 SP7 allows remote attackers to cause a denial of service (disk consumption) via requests containing malformed headers, which cause a large amount of data to be written to the server log.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/215" source="BEA" patch="1" adv="1">BEA07-148.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/32859" source="OSVDB">32859</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers prev="1" num="6.1" edition="sp7"/>
        <vers prev="1" num="7.0" edition="sp7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0422" published="2007-01-22" name="CVE-2007-0422" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BEA WebLogic Server 9.0, 9.1, and 9.2 Gold, when running on Solaris 9, allows remote attackers to cause a denial of service (server inaccessibility) via manipulated socket connections.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/217" source="BEA" patch="1" adv="1">BEA07-150.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/32858" source="OSVDB">32858</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="9.0"/>
        <vers num="9.1"/>
        <vers num="9.2" edition="ga"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0423" published="2007-01-22" name="CVE-2007-0423" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">BEA WebLogic Portal 9.2 does not properly handle when an administrator deletes entitlements for a role, which causes other role entitlements to be "inadvertently affected," which has an unknown impact.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/218" source="BEA" patch="1" adv="1">BEA07-151.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/32857" source="OSVDB">32857</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
      <ref url="http://securitytracker.com/id?1017521" source="SECTRACK">1017521</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_portal">
        <vers num="9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0424" published="2007-01-22" name="CVE-2007-0424" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the BEA WebLogic Server proxy plug-in for Netscape Enterprise Server before September 2006 for Netscape Enterprise Server allow remote attackers to cause a denial of service via certain requests that trigger errors that lead to a server being marked as unavailable, hosting web server failure, or CPU consumption.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/219" source="BEA" patch="1" adv="1">BEA07-152.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/32856" source="OSVDB">32856</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0425" published="2007-01-22" name="CVE-2007-0425" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in BEA WebLogic Platform and Server 8.1 through 8.1 SP5, and JRockit 1.4.2 R4.5 and earlier, allows attackers to gain privileges via unspecified vectors, related to an "overflow condition," probably a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA" adv="1">23750</ref>
      <ref url="http://osvdb.org/38515" source="OSVDB">38515</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/222" source="BEA" adv="1">BEA07-155.00</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="jrockit">
        <vers prev="1" num="1.4.2" edition="r24.5"/>
      </prod>
      <prod vendor="bea" name="weblogic_server">
        <vers prev="1" num="8.1" edition="sp5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0426" published="2007-01-22" name="CVE-2007-0426" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">BEA WebLogic Portal 9.2, when running in a WebLogic Server clustered environment using WebLogic Portal entitlements, does not properly propagate entitlement policy changes if the changes are made on a managed server while the Administrative Server is unavailable, which might allow attackers to bypass intended restrictions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/223" source="BEA" patch="1" adv="1">BEA07-156.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA" adv="1">23750</ref>
      <ref url="http://osvdb.org/38516" source="OSVDB">38516</ref>
      <ref url="http://osvdb.org/32854" source="OSVDB">32854</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
      <ref url="http://securitytracker.com/id?1017521" source="SECTRACK">1017521</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_portal">
        <vers num="9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0427" published="2007-01-22" name="CVE-2007-0427" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a help project (.HPJ) file with a long HLP field in the OPTIONS section.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22135" source="BID">22135</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457436/100/0/threaded" source="BUGTRAQ" adv="1">20070119 Help project files (.HPJ) buffer overflow vulnerability in Microsoft Help Workshop</ref>
      <ref url="http://www.anspi.pl/~porkythepig/visualization/hpj-x01.cpp" source="MISC">http://www.anspi.pl/~porkythepig/visualization/hpj-x01.cpp</ref>
      <ref url="http://osvdb.org/31899" source="OSVDB">31899</ref>
      <ref url="http://securityreason.com/securityalert/2177" source="SREASON">2177</ref>
      <ref url="http://secunia.com/advisories/23862" source="SECUNIA">23862</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="html_help_workshop">
        <vers num="4.03.0002"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0428" published="2007-01-22" name="CVE-2007-0428" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the chtbl_lookup function in hash.c for WzdFTPD 8.0 and earlier allows remote attackers to cause a denial of service via a crafted FTP command, probably due to a NULL pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31599" source="XF">wzdftpd-ftp-dos(31599)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0277" source="VUPEN">ADV-2007-0277</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457454/100/0/threaded" source="BUGTRAQ" adv="1">20070119 WzdFTPD &lt; 8.1 Denial of service</ref>
      <ref url="http://www.s21sec.com/avisos/s21sec-033-en.txt" source="MISC" adv="1">http://www.s21sec.com/avisos/s21sec-033-en.txt</ref>
      <ref url="http://securitytracker.com/id?1017537" source="SECTRACK" adv="1">1017537</ref>
      <ref url="http://osvdb.org/32941" source="OSVDB">32941</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051896.html" source="FULLDISC" adv="1">20070119 WzdFTPD &lt; 8.1 Denial of service</ref>
      <ref url="http://securityreason.com/securityalert/2171" source="SREASON">2171</ref>
      <ref url="http://secunia.com/advisories/23852" source="SECUNIA">23852</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wzdftpd" name="wzdftpd">
        <vers prev="1" num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0429" published="2007-01-22" name="CVE-2007-0429" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">DivXBrowserPlugin (aka DivX Web Player) npdivx32.dll, as distributed with DivX Player 6.4.1, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) by invoking the GoWindowed method for a certain instance of the ActiveX object.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31601" source="XF">divx-divxbrowserplugin-dos(31601)</ref>
      <ref url="http://www.securityfocus.com/bid/22133" source="BID">22133</ref>
      <ref url="http://osvdb.org/37693" source="OSVDB">37693</ref>
      <ref url="http://milw0rm.com/exploits/3157" source="MILW0RM">3157</ref>
    </refs>
    <vuln_soft>
      <prod vendor="divx" name="divx_player">
        <vers num="6.4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0430" published="2007-01-22" name="CVE-2007-0430" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The shared_region_map_file_np function in Apple Mac OS X 10.4.8 and earlier kernel allows local users to cause a denial of service (memory corruption) via a large mappingCount value.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0275" source="VUPEN">ADV-2007-0275</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457466/100/0/threaded" source="BUGTRAQ" adv="1">20070119 [RISE-2007001] Apple Mac OS X 10.4.x kernel shared_region_map_file_np() memory corruption vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31645" source="XF">macos-sharedregionmapfilenp-dos(31645)</ref>
      <ref url="http://www.osvdb.org/32942" source="OSVDB">32942</ref>
      <ref url="http://securitytracker.com/id?1017538" source="SECTRACK">1017538</ref>
      <ref url="http://securityreason.com/securityalert/2178" source="SREASON">2178</ref>
      <ref url="http://secunia.com/advisories/23823" source="SECUNIA">23823</ref>
      <ref url="http://risesecurity.org/advisory.php?id=RISE-2007001.txt" source="MISC">http://risesecurity.org/advisory.php?id=RISE-2007001.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers prev="1" num="10.4.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0431" published="2007-01-22" name="CVE-2007-0431" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">AVM Fritz!Box 7050, and possibly other product models, allows remote attackers to cause a denial of service (VoIP application crash) via a zero-length UDP packet to the SIP port (port 5060).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0272" source="VUPEN">ADV-2007-0272</ref>
      <ref url="http://www.securityfocus.com/bid/22130" source="BID">22130</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457406/100/0/threaded" source="BUGTRAQ">20070119 DoS against AVM Fritz!Box 7050 (and others)</ref>
      <ref url="http://osvdb.org/32940" source="OSVDB">32940</ref>
      <ref url="http://mazzoo.de/blog/2007/01/18#FritzBox_DoS" source="MISC">http://mazzoo.de/blog/2007/01/18#FritzBox_DoS</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0387.html" source="FULLDISC">20070119 DoS against AVM Fritz!Box 7050 (and others)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31633" source="XF">fritzbox-udp-packet-dos(31633)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457829/100/0/threaded" source="BUGTRAQ">20070123 Re: DoS against AVM Fritz!Box 7050 (and others)</ref>
      <ref url="http://secunia.com/advisories/23868" source="SECUNIA">23868</ref>
      <ref url="ftp://ftp.avm.de/fritz.box/fritzbox.fon_wlan_7050/firmware/info.txt" source="CONFIRM">ftp://ftp.avm.de/fritz.box/fritzbox.fon_wlan_7050/firmware/info.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avm" name="fritzbox">
        <vers num="7050"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0432" published="2007-01-22" name="CVE-2007-0432" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">BEA AquaLogic Service Bus 2.0, 2.1, and 2.5 does not properly reject malformed request messages to a proxy service, which might allow remote attackers to bypass authorization policies and route requests to back-end services or conduct other unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1017523" source="SECTRACK" adv="1">1017523</ref>
      <ref url="http://secunia.com/advisories/23786" source="SECUNIA" adv="1">23786</ref>
      <ref url="http://osvdb.org/32862" source="OSVDB">32862</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/224" source="BEA" adv="1">BEA07-157.00</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="aqualogic_service_bus">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0433" published="2007-01-22" name="CVE-2007-0433" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2, when using Active Directory LDAP for authentication, allows remote authenticated users to access the server even after the account has been disabled.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1017524" source="SECTRACK" adv="1">1017524</ref>
      <ref url="http://secunia.com/advisories/23786" source="SECUNIA" adv="1">23786</ref>
      <ref url="http://osvdb.org/32861" source="OSVDB">32861</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/221" source="BEA" adv="1">BEA07-154.00</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="aqualogic_service_bus">
        <vers num="2.0" edition="sp1"/>
        <vers num="2.0" edition="sp2"/>
        <vers num="2.1" edition="sp1"/>
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0434" published="2007-01-22" name="CVE-2007-0434" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2 does not properly set the severity level of audit events when the system load is high, which might make it easier for attackers to avoid detection.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23786" source="SECUNIA" adv="1">23786</ref>
      <ref url="http://osvdb.org/32860" source="OSVDB">32860</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/220" source="BEA" adv="1">BEA07-153.00</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="aqualogic_enterprise_security">
        <vers num="2.0" edition="sp1"/>
        <vers num="2.0" edition="sp2"/>
        <vers num="2.1" edition="sp1"/>
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0435" published="2007-01-22" name="CVE-2007-0435" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">T-Com Speedport 500V routers with firmware 1.31 allow remote attackers to bypass authentication and reconfigure the device via a LOGINKEY=TECOM cookie value.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457453/100/0/threaded" source="BUGTRAQ" adv="1">20070119 Virginity Security Advisory 2007-001 : T-Com Speedport 500V Login bypass</ref>
      <ref url="http://osvdb.org/32995" source="OSVDB">32995</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31621" source="XF">tcom-login-authentication-bypass(31621)</ref>
      <ref url="http://www.securityfocus.com/bid/22160" source="BID">22160</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460319/100/0/threaded" source="BUGTRAQ">20070216 Re: Virginity Security Advisory 2007-001 : T-Com Speedport 500V Login bypass</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457656/100/0/threaded" source="BUGTRAQ">20070122 Re: Virginity Security Advisory 2007-001 : T-Com Speedport 500V Login bypass</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457645/100/0/threaded" source="BUGTRAQ">20070121 Re: Virginity Security Advisory 2007-001 : T-Com Speedport 500V Login bypass</ref>
      <ref url="http://secunia.com/advisories/23853" source="SECUNIA">23853</ref>
    </refs>
    <vuln_soft>
      <prod vendor="t-com" name="speedport_500v">
        <vers num="firmware_1.31"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0436" published="2007-02-03" name="CVE-2007-0436" modified="2011-05-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Barron McCann X-Kryptor Driver BMS1446HRR (Xgntr BMS1351 Install BMS1472) in X-Kryptor Secure Client does not drop privileges when launching an Explorer window in response to a help command, which allows local users to gain LocalSystem privileges via interactive use of Explorer.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0496" source="VUPEN" adv="1">ADV-2007-0496</ref>
      <ref url="http://www.securityfocus.com/bid/22424" source="BID">22424</ref>
      <ref url="http://www.cpni.gov.uk/Products/vulnerabilitydisclosures/default.aspx?id=va-20070129-0107.xml" source="MISC">http://www.cpni.gov.uk/Products/vulnerabilitydisclosures/default.aspx?id=va-20070129-0107.xml</ref>
      <ref url="http://www.cpni.gov.uk/Products/advisories/default.aspx?id=al-20070129-0107.xml" source="MISC">http://www.cpni.gov.uk/Products/advisories/default.aspx?id=al-20070129-0107.xml</ref>
      <ref url="http://www.bemacpromotions.com/files/xkpatch462660.zip" source="CONFIRM">http://www.bemacpromotions.com/files/xkpatch462660.zip</ref>
      <ref url="http://www.barronmccann.com/ISec/s2pressrelease.asp?PRID=141&amp;S2ID=14" source="CONFIRM">http://www.barronmccann.com/ISec/s2pressrelease.asp?PRID=141&amp;S2ID=14</ref>
      <ref url="http://secunia.com/advisories/24045" source="SECUNIA" adv="1">24045</ref>
      <ref url="http://osvdb.org/33110" source="OSVDB">33110</ref>
      <ref url="http://jvn.jp/niscc/NISCC-462660/index.html" source="MISC">http://jvn.jp/niscc/NISCC-462660/index.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="barron_mccann" name="install">
        <vers num="bms1472"/>
      </prod>
      <prod vendor="barron_mccann" name="x-kryptor_driver">
        <vers num="bms1446hrr"/>
      </prod>
      <prod vendor="barron_mccann" name="x-kryptor_secure_client">
        <vers num=""/>
      </prod>
      <prod vendor="barron_mccann" name="xgntr">
        <vers num="bms1351"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0437" published="2007-08-20" name="CVE-2007-0437" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the sample Cache' Server Page (CSP) scripts in InterSystems Cache' allow remote attackers to inject arbitrary web script or HTML via (1) the TO parameter to loop.csp, (2) the VALUE parameter to cookie.csp, and (3) the PAGE parameter to showsource.csp in csp/samples/; and allow remote authenticated users to inject arbitrary web script or HTML via (4) the ERROR parameter to csp/samples/xmlclasseserror.csp, and unspecified vectors in (5) object.csp and (6) lotteryhistory.csp in csp/samples/.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.mwrinfosecurity.com/news/1658.html" source="MISC">http://www.mwrinfosecurity.com/news/1658.html</ref>
      <ref url="http://www.mwrinfosecurity.com/advisories/mwri_cache-sample-files-xss-advisory_2007-04-04.pdf" source="MISC">http://www.mwrinfosecurity.com/advisories/mwri_cache-sample-files-xss-advisory_2007-04-04.pdf</ref>
      <ref url="http://www.cpni.gov.uk/Products/alerts/2928.aspx" source="MISC">http://www.cpni.gov.uk/Products/alerts/2928.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intersystems" name="cache_database">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0441" published="2007-01-23" name="CVE-2007-0441" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, and 7.50 allows remote attackers to execute arbitrary commands via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456623/100/100/threaded" source="HP" patch="1" adv="1">SSRT05103</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0153" source="VUPEN">ADV-2007-0153</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456623/100/100/threaded" source="HP">SSRT05103</ref>
      <ref url="http://securitytracker.com/id?1017504" source="SECTRACK" adv="1">1017504</ref>
      <ref url="http://osvdb.org/32728" source="OSVDB">32728</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="6.20"/>
        <vers num="6.41"/>
        <vers num="7.0.1"/>
        <vers num="7.50"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0442" published="2007-01-23" name="CVE-2007-0442" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in IBM OS/400 R530 and R535 has unknown impact and remote attack vectors, related to an "Integrity Problem" involving LIC-TCPIP and TCP reset.  NOTE: it is possible that this issue is related to CVE-2004-0230, but this is not certain.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=nas2c8623b2ed01d45d08625718e0043edc2" source="AIXAPAR">MA33860</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=nas204b3e62c8a63af708625718e0043eddc" source="AIXAPAR">MA33861</ref>
      <ref url="http://secunia.com/advisories/23765" source="SECUNIA" adv="1">23765</ref>
      <ref url="http://osvdb.org/32812" source="OSVDB">32812</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="os_400">
        <vers num="r530"/>
        <vers num="r535"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0443" published="2007-04-24" name="CVE-2007-0443" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple buffer overflows in the CDDBControl ActiveX control in Gracenote CDDB before 20070418 allow remote attackers to execute arbitrary code via long values for certain Proxy configuration parameters.</descript>
    </desc>
    <sols>
      <sol source="nvd">The vendor has address this issue with the following information: http://www.gracenote.com/corporate/FAQs.html/faqset=update/page=0</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-021.html" source="MISC" patch="1" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-07-021.html</ref>
      <ref url="http://www.securityfocus.com/bid/23567" source="BID" patch="1">23567</ref>
      <ref url="http://secunia.com/advisories/22924" source="SECUNIA" patch="1" adv="1">22924</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1475" source="VUPEN">ADV-2007-1475</ref>
      <ref url="http://www.securitytracker.com/id?1017937" source="SECTRACK">1017937</ref>
      <ref url="http://www.gracenote.com/corporate/FAQs.html/faqset=update/page=0" source="CONFIRM">http://www.gracenote.com/corporate/FAQs.html/faqset=update/page=0</ref>
      <ref url="http://osvdb.org/34327" source="OSVDB">34327</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33773" source="XF">cddbcontrol-activex-bo(33773)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466403/100/0/threaded" source="BUGTRAQ">20070420 ZDI-07-021: GraceNote CDDBControl ActiveX Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gracenote" name="cddbcontrol_activex_control">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0444" published="2007-01-24" name="CVE-2007-0444" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the print provider library (cpprov.dll) in Citrix Presentation Server 4.0, MetaFrame Presentation Server 3.0, and MetaFrame XP 1.0 allows local users and remote attackers to execute arbitrary code via long arguments to the (1) EnumPrintersW and (2) OpenPrinter functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-006.html" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-07-006.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0328" source="VUPEN" adv="1">ADV-2007-0328</ref>
      <ref url="http://www.securityfocus.com/data/vulnerabilities/exploits/testlpc.c" source="MISC">http://www.securityfocus.com/data/vulnerabilities/exploits/testlpc.c</ref>
      <ref url="http://www.securityfocus.com/bid/22217" source="BID">22217</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458002/100/0/threaded" source="BUGTRAQ">20070124 ZDI-07-006: Citrix Metaframe Presentation Server Print Provider Buffer Overflow Vulnerability</ref>
      <ref url="http://support.citrix.com/article/CTX111686" source="CONFIRM" adv="1">http://support.citrix.com/article/CTX111686</ref>
      <ref url="http://securitytracker.com/id?1017553" source="SECTRACK">1017553</ref>
      <ref url="http://secunia.com/advisories/23869" source="SECUNIA" adv="1">23869</ref>
      <ref url="http://osvdb.org/32958" source="OSVDB">32958</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citrix" name="metaframe">
        <vers num="1.0" edition=""/>
        <vers num="1.0" edition=":xp"/>
      </prod>
      <prod vendor="citrix" name="metaframe_presentation_server">
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0445" published="2007-04-05" name="CVE-2007-0445" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the arj.ppl module in the OnDemand Scanner in Kaspersky Anti-Virus, Anti-Virus for Workstations, and Anti-Virus for File Servers 6.0, and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows remote attackers to execute arbitrary code via crafted ARJ archives.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kaspersky.com/technews?id=203038694" source="CONFIRM" patch="1">http://www.kaspersky.com/technews?id=203038694</ref>
      <ref url="http://www.kaspersky.com/technews?id=203038693" source="CONFIRM" patch="1">http://www.kaspersky.com/technews?id=203038693</ref>
      <ref url="http://secunia.com/advisories/24778" source="SECUNIA" patch="1" adv="1">24778</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-013.html" source="MISC" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-07-013.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1268" source="VUPEN">ADV-2007-1268</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33489" source="XF">kaspersky-arj-bo(33489)</ref>
      <ref url="http://www.securitytracker.com/id?1017883" source="SECTRACK">1017883</ref>
      <ref url="http://www.securitytracker.com/id?1017882" source="SECTRACK">1017882</ref>
      <ref url="http://www.securityfocus.com/bid/23346" source="BID">23346</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464878/100/0/threaded" source="BUGTRAQ">20070405 ZDI-07-013: Kaspersky AntiVirus Engine ARJ Archive Parsing Heap Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kaspersky_lab" name="kaspersky_anti-virus">
        <vers num="6.0" edition=""/>
        <vers num="6.0" edition=":file_servers"/>
        <vers num="6.0" edition=":workstations"/>
        <vers num="6.0" edition=":windows_workstation"/>
      </prod>
      <prod vendor="kaspersky_lab" name="kaspersky_internet_security">
        <vers prev="1" num="6.0" edition="maintenance_pack_2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0446" published="2007-02-08" name="CVE-2007-0446" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in magentproc.exe for Hewlett-Packard Mercury LoadRunner Agent 8.0 and 8.1, Performance Center Agent 8.0 and 8.1, and Monitor over Firewall 8.1 allows remote attackers to execute arbitrary code via a packet with a long server_ip_name field to TCP port 54345, which triggers the overflow in mchan.dll.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/303012" source="CERT-VN">VU#303012</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00854250" source="HP" patch="1" adv="1">SSRT061280</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-007.html" source="MISC" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-07-007.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0535" source="VUPEN">ADV-2007-0535</ref>
      <ref url="http://osvdb.org/33132" source="OSVDB">33132</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00854250" source="HP">SSRT061280</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32390" source="XF">mercury-multiple-agent-bo(32390)</ref>
      <ref url="http://www.securityfocus.com/bid/22487" source="BID">22487</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459505/100/0/threaded" source="BUGTRAQ">20070208 ZDI-07-007: HP Mercury LoadRunner Agent Stack Overflow Vulnerability</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/r-123.shtml" source="CIAC">R-123</ref>
      <ref url="http://securitytracker.com/id?1017613" source="SECTRACK">1017613</ref>
      <ref url="http://securitytracker.com/id?1017612" source="SECTRACK">1017612</ref>
      <ref url="http://securitytracker.com/id?1017611" source="SECTRACK">1017611</ref>
      <ref url="http://secunia.com/advisories/24112" source="SECUNIA">24112</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="mercury_loadrunner_agent">
        <vers num="8.0"/>
        <vers num="8.1"/>
      </prod>
      <prod vendor="hp" name="mercury_monitor_over_firewall">
        <vers num="8.1"/>
      </prod>
      <prod vendor="hp" name="mercury_performance_center_agent">
        <vers num="8.0"/>
        <vers num="8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0447" published="2007-10-05" name="CVE-2007-0447" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2007.07.11f.html" source="CONFIRM" patch="1">http://securityresponse.symantec.com/avcenter/security/Content/2007.07.11f.html</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-040.html" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-07-040.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2508" source="VUPEN">ADV-2007-2508</ref>
      <ref url="http://www.securityfocus.com/bid/24282" source="BID">24282</ref>
      <ref url="http://secunia.com/advisories/26053" source="SECUNIA" adv="1">26053</ref>
      <ref url="http://osvdb.org/36118" source="OSVDB">36118</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="antivirus_scan_engine">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":clearswift"/>
        <vers num="4.1"/>
        <vers num="4.1.8"/>
        <vers num="4.3" edition=""/>
        <vers num="4.3" edition=":clearswift"/>
        <vers num="4.3" edition=":caching"/>
        <vers num="4.3" edition=":microsoft_sharepoint"/>
        <vers num="4.3" edition=":network_attached_storage"/>
        <vers num="4.3.12" edition=""/>
        <vers num="4.3.12" edition=":messaging"/>
        <vers num="4.3.12" edition=":microsoft_sharepoint"/>
        <vers num="4.3.12" edition=":network_attached_storage"/>
        <vers num="4.3.12" edition=":clearswift"/>
        <vers num="4.3.12" edition=":caching"/>
        <vers num="4.3.3"/>
        <vers num="4.3.7.27"/>
        <vers num="4.3.8.29"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
      </prod>
      <prod vendor="symantec" name="brightmail_antispam">
        <vers num="4.0"/>
        <vers num="5.5"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
      </prod>
      <prod vendor="symantec" name="client_security">
        <vers num="2.0" edition=""/>
        <vers num="2.0" edition=":scf_7.1"/>
        <vers num="2.0" edition="build_9.0.0.338"/>
        <vers num="2.0" edition="build_9.0.0.338:stm"/>
        <vers num="2.0.1_build_9.0.1.1000" edition="mr1"/>
        <vers num="2.0.2_build_9.0.2.1000" edition="mr2"/>
        <vers num="2.0.3_build_9.0.3.1000" edition="mr3"/>
        <vers num="2.0.4" edition="mr4_build1000"/>
        <vers num="2.0.5_build_1100_mp1" edition="mr5"/>
        <vers num="2.0.6" edition="mr6"/>
        <vers num="3.0"/>
        <vers num="3.0.0.359"/>
        <vers num="3.0.1.1000"/>
        <vers num="3.0.1.1001"/>
        <vers num="3.0.1.1007"/>
        <vers num="3.0.1.1008"/>
        <vers num="3.0.2.2000"/>
        <vers num="3.0.2.2001"/>
        <vers num="3.0.2.2002"/>
        <vers num="3.0.2.2010"/>
        <vers num="3.0.2.2011"/>
        <vers num="3.0.2.2020"/>
        <vers num="3.0.2.2021"/>
        <vers num="3.1"/>
        <vers num="3.1.394"/>
        <vers num="3.1.396"/>
        <vers num="3.1.400"/>
        <vers num="3.1.401"/>
      </prod>
      <prod vendor="symantec" name="mail_security">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":microsoft_exchange"/>
        <vers num="4.0" edition=":domino"/>
        <vers num="4.0" edition="build456"/>
        <vers num="4.0" edition="build456:microsoft_exchange"/>
        <vers num="4.0" edition="build463"/>
        <vers num="4.0" edition="build463:microsoft_exchange"/>
        <vers num="4.0" edition="build465"/>
        <vers num="4.0" edition="build465:microsoft_exchange"/>
        <vers num="4.0" edition="build736"/>
        <vers num="4.0" edition="build736:microsoft_exchange"/>
        <vers num="4.0" edition="build741"/>
        <vers num="4.0" edition="build741:microsoft_exchange"/>
        <vers num="4.0" edition="build743"/>
        <vers num="4.0" edition="build743:microsoft_exchange"/>
        <vers num="4.0.1" edition=""/>
        <vers num="4.0.1" edition=":domino"/>
        <vers num="4.1" edition="build458"/>
        <vers num="4.1" edition="build458:microsoft_exchange"/>
        <vers num="4.1" edition="build459"/>
        <vers num="4.1" edition="build459:microsoft_exchange"/>
        <vers num="4.1" edition="build461"/>
        <vers num="4.1" edition="build461:microsoft_exchange"/>
        <vers num="4.5" edition=""/>
        <vers num="4.5" edition=":microsoft_exchange"/>
        <vers num="4.5.4.743" edition=""/>
        <vers num="4.5.4.743" edition=":microsoft_exchange"/>
        <vers num="4.5_build_719" edition=""/>
        <vers num="4.5_build_719" edition=":exchange"/>
        <vers num="4.5_build_736" edition=""/>
        <vers num="4.5_build_736" edition=":exchange"/>
        <vers num="4.5_build_741" edition=""/>
        <vers num="4.5_build_741" edition=":exchange"/>
        <vers num="4.6.1.107" edition=""/>
        <vers num="4.6.1.107" edition=":microsoft_exchange"/>
        <vers num="4.6.3" edition=""/>
        <vers num="4.6.3" edition=":microsoft_exchange"/>
        <vers num="4.6_build_97" edition=""/>
        <vers num="4.6_build_97" edition=":exchange"/>
        <vers num="5.0" edition=""/>
        <vers num="5.0" edition=":smtp"/>
        <vers num="5.0" edition=":microsoft_exchange"/>
        <vers num="5.0.0.204" edition=""/>
        <vers num="5.0.0.204" edition=":microsoft_exchange"/>
        <vers num="5.0.1" edition=""/>
        <vers num="5.0.1" edition=":smtp"/>
        <vers num="5.1.0" edition=""/>
        <vers num="5.1.0" edition=":domino"/>
        <vers num="6.0.0" edition=""/>
        <vers num="6.0.0" edition=":microsoft_exchange"/>
      </prod>
      <prod vendor="symantec" name="norton_antivirus">
        <vers num="" edition=":corporate_edition_for_linux"/>
        <vers num="10.0" edition=""/>
        <vers num="10.0" edition=":corporate_edition"/>
        <vers num="10.0" edition=":macintosh"/>
        <vers num="10.0.0" edition=""/>
        <vers num="10.0.0" edition=":macintosh"/>
        <vers num="10.0.0.359" edition=""/>
        <vers num="10.0.0.359" edition=":corporate_edition"/>
        <vers num="10.0.1" edition=""/>
        <vers num="10.0.1" edition=":macintosh"/>
        <vers num="10.0.1.1000" edition=""/>
        <vers num="10.0.1.1000" edition=":corporate_edition"/>
        <vers num="10.0.1.1007" edition=""/>
        <vers num="10.0.1.1007" edition=":corporate_edition"/>
        <vers num="10.0.1.1008" edition=""/>
        <vers num="10.0.1.1008" edition=":corporate_edition"/>
        <vers num="10.0.2.2000" edition=""/>
        <vers num="10.0.2.2000" edition=":corporate_edition"/>
        <vers num="10.0.2.2001" edition=""/>
        <vers num="10.0.2.2001" edition=":corporate_edition"/>
        <vers num="10.0.2.2002" edition=""/>
        <vers num="10.0.2.2002" edition=":corporate_edition"/>
        <vers num="10.0.2.2010" edition=""/>
        <vers num="10.0.2.2010" edition=":corporate_edition"/>
        <vers num="10.0.2.2011" edition=""/>
        <vers num="10.0.2.2011" edition=":corporate_edition"/>
        <vers num="10.0.2.2020" edition=""/>
        <vers num="10.0.2.2020" edition=":corporate_edition"/>
        <vers num="10.0.2.2021" edition=""/>
        <vers num="10.0.2.2021" edition=":corporate_edition"/>
        <vers num="10.1" edition=""/>
        <vers num="10.1" edition=":corporate_edition"/>
        <vers num="10.1.394" edition=""/>
        <vers num="10.1.394" edition=":corporate_edition"/>
        <vers num="10.1.396" edition=""/>
        <vers num="10.1.396" edition=":corporate_edition"/>
        <vers num="10.1.4" edition=""/>
        <vers num="10.1.4" edition=":corporate_edition"/>
        <vers num="10.1.4" edition="mr4_mp1_build4010"/>
        <vers num="10.1.4" edition="mr4_mp1_build4010:corporate_edition"/>
        <vers num="10.1.4.4010" edition=""/>
        <vers num="10.1.4.4010" edition=":corporate_edition"/>
        <vers num="10.1.400" edition=""/>
        <vers num="10.1.400" edition=":corporate_edition"/>
        <vers num="10.1.401" edition=""/>
        <vers num="10.1.401" edition=":corporate_edition"/>
        <vers num="10.9.1" edition=""/>
        <vers num="10.9.1" edition=":macintosh"/>
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":professional"/>
        <vers num="2005" edition=""/>
        <vers num="2005" edition=":professional"/>
        <vers num="2005" edition="11.0"/>
        <vers num="2005" edition="11.0.9"/>
        <vers num="2006"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":macintosh"/>
        <vers num="9.0" edition=":corporate_edition"/>
        <vers num="9.0.0" edition=""/>
        <vers num="9.0.0" edition=":macintosh"/>
        <vers num="9.0.0.338" edition=""/>
        <vers num="9.0.0.338" edition=":corporate_edition"/>
        <vers num="9.0.1" edition=""/>
        <vers num="9.0.1" edition=":macintosh"/>
        <vers num="9.0.1.1.1000" edition=""/>
        <vers num="9.0.1.1.1000" edition=":corporate_edition"/>
        <vers num="9.0.2" edition=""/>
        <vers num="9.0.2" edition=":macintosh"/>
        <vers num="9.0.2.1000" edition=""/>
        <vers num="9.0.2.1000" edition=":corporate_edition"/>
        <vers num="9.0.3" edition=""/>
        <vers num="9.0.3" edition=":macintosh"/>
        <vers num="9.0.3.1000" edition=""/>
        <vers num="9.0.3.1000" edition=":corporate_edition"/>
        <vers num="9.0.4" edition=""/>
        <vers num="9.0.4" edition=":corporate_edition"/>
        <vers num="9.0.4" edition="mr4_build_1000"/>
        <vers num="9.0.4" edition="mr4_build_1000:corporate_edition"/>
        <vers num="9.0.5" edition=""/>
        <vers num="9.0.5" edition=":corporate_edition"/>
        <vers num="9.0.5.1100" edition=""/>
        <vers num="9.0.5.1100" edition=":corporate_edition"/>
        <vers num="9.0.6.1000" edition=""/>
        <vers num="9.0.6.1000" edition=":corporate_edition"/>
      </prod>
      <prod vendor="symantec" name="norton_internet_security">
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":professional"/>
        <vers num="2005" edition=""/>
        <vers num="2005" edition=":professional"/>
        <vers num="2005" edition="11.0"/>
        <vers num="2005" edition="11.0.9"/>
        <vers num="2005" edition="11.5.6.14"/>
        <vers num="2006" edition=""/>
        <vers num="2006" edition=":professional"/>
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":macintosh"/>
      </prod>
      <prod vendor="symantec" name="norton_personal_firewall">
        <vers num="2006"/>
        <vers num="2006_9.1.0.33"/>
        <vers num="2006_9.1.1.7"/>
      </prod>
      <prod vendor="symantec" name="norton_system_works">
        <vers num="2004"/>
        <vers num="2005" edition=""/>
        <vers num="2005" edition=":premier"/>
        <vers num="2005" edition="11.0"/>
        <vers num="2005" edition="11.0.9"/>
        <vers num="2006"/>
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":macintosh"/>
      </prod>
      <prod vendor="symantec" name="symantec_antivirus_filtering_+for_domino">
        <vers num="3.0.12"/>
      </prod>
      <prod vendor="symantec" name="web_security">
        <vers num="2.5"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1.70"/>
        <vers num="3.0.1.76"/>
        <vers num="3.0.1_build_3.01.70"/>
        <vers num="3.0.1_build_3.01.72"/>
        <vers num="3.0.1_build_3.01.74"/>
        <vers num="3.01.59"/>
        <vers num="3.01.60"/>
        <vers num="3.01.61"/>
        <vers num="3.01.62"/>
        <vers num="3.01.63"/>
        <vers num="3.01.67"/>
        <vers num="3.01.68"/>
        <vers num="5.0" edition=""/>
        <vers num="5.0" edition=":microsoft_isa_2004"/>
      </prod>
      <prod vendor="symantec" name="gateway_security_5000_series">
        <vers num="3.0.1"/>
      </prod>
      <prod vendor="symantec" name="gateway_security_5400">
        <vers num="2.0.1"/>
      </prod>
      <prod vendor="symantec" name="mail_security_8820_appliance">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0448" published="2007-05-24" name="CVE-2007-0448" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The fopen function in PHP 5.2.0 does not properly handle invalid URI handlers, which allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files via a file path specified with an invalid URI, as demonstrated via the srpath URI.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22261" source="BID">22261</ref>
      <ref url="http://securityreason.com/achievement_securityalert/44" source="SREASONRES">20070125 PHP 5.2.0 safe_mode bypass (by Writing Mode)</ref>
      <ref url="http://securityreason.com/securityalert/2175" source="SREASON">2175</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0449" published="2007-01-23" name="CVE-2007-0449" modified="2011-09-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.1 SP1, Mobile Backup r4.0, Desktop and Business Protection Suite r2, and Desktop Management Suite (DMS) r11.0 and r11.1 allow remote attackers to execute arbitrary code via crafted packets to TCP port (1) 1900 or (2) 2200.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/611276" source="CERT-VN">VU#611276</ref>
      <ref url="http://www.kb.cert.org/vuls/id/357308" source="CERT-VN">VU#357308</ref>
      <ref url="http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/babldimpsec-notice.asp" source="CONFIRM" patch="1">http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/babldimpsec-notice.asp</ref>
      <ref url="http://secunia.com/advisories/23897" source="SECUNIA" patch="1" adv="1">23897</ref>
      <ref url="http://www3.ca.com/securityadvisor/vulninfo/Vuln.aspx?ID=34993" source="CONFIRM">http://www3.ca.com/securityadvisor/vulninfo/Vuln.aspx?ID=34993</ref>
      <ref url="http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=97696" source="CONFIRM">http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=97696</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0314" source="VUPEN" adv="1">ADV-2007-0314</ref>
      <ref url="http://www.securityfocus.com/bid/22342" source="BID">22342</ref>
      <ref url="http://www.securityfocus.com/bid/22340" source="BID">22340</ref>
      <ref url="http://www.securityfocus.com/bid/22199" source="BID">22199</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458648/100/0/threaded" source="BUGTRAQ">20070131 Remote Unauthenticated Code Execution II CA BrightStor ARCserve Backup for Laptops &amp; Desktops</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458644/100/0/threaded" source="BUGTRAQ">20070131 Remote Unauthenticated Code Execution CA BrightStor ARCserve Backup</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457945/30/8460/threaded" source="BUGTRAQ">20070124 [CAID 34993]: CA BrightStor ARCserve Backup for Laptops and Desktops Multiple Overflow Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/31593" source="OSVDB">31593</ref>
      <ref url="http://securitytracker.com/id?1017548" source="SECTRACK">1017548</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="brightstor_arcserve_backup_laptops_desktops">
        <vers num="11.0"/>
        <vers num="11.1" edition="sp1"/>
      </prod>
      <prod vendor="ca" name="brightstor_mobile_backup">
        <vers num="r4.0"/>
      </prod>
      <prod vendor="ca" name="business_protection_suite">
        <vers num="2.0"/>
      </prod>
      <prod vendor="ca" name="desktop_management_suite">
        <vers num="11.0"/>
        <vers num="11.1"/>
      </prod>
      <prod vendor="ca" name="desktop_protection_suite">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0450" published="2007-03-16" name="CVE-2007-0450" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) "/" (slash), (2) "\" (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462791/100/0/threaded" source="BUGTRAQ" patch="1">20070314 SEC Consult SA-20070314-0 :: Apache HTTP Server / Tomcat directory traversal</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32988" source="XF">tomcat-proxy-directory-traversal(32988)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0233" source="VUPEN">ADV-2009-0233</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1979/references" source="VUPEN">ADV-2008-1979</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0065" source="VUPEN">ADV-2008-0065</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3386" source="VUPEN">ADV-2007-3386</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3087" source="VUPEN">ADV-2007-3087</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2732" source="VUPEN">ADV-2007-2732</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0975" source="VUPEN">ADV-2007-0975</ref>
      <ref url="http://www.securityfocus.com/bid/22960" source="BID">22960</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500412/100/0/threaded" source="BUGTRAQ">20090127 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities (Updated - v1.1)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500396/100/0/threaded" source="BUGTRAQ">20090124 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities</ref>
      <ref url="http://www.sec-consult.com/fileadmin/Advisories/20070314-0-apache_tomcat_directory_traversal.txt" source="MISC">http://www.sec-consult.com/fileadmin/Advisories/20070314-0-apache_tomcat_directory_traversal.txt</ref>
      <ref url="http://www.sec-consult.com/287.html" source="MISC">http://www.sec-consult.com/287.html</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0327.html" source="REDHAT">RHSA-2007:0327</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_5_sr.html" source="SUSE">SUSE-SR:2007:005</ref>
      <ref url="http://tomcat.apache.org/security-6.html" source="CONFIRM">http://tomcat.apache.org/security-6.html</ref>
      <ref url="http://tomcat.apache.org/security-5.html" source="CONFIRM">http://tomcat.apache.org/security-5.html</ref>
      <ref url="http://tomcat.apache.org/security-4.html" source="CONFIRM">http://tomcat.apache.org/security-4.html</ref>
      <ref url="http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540" source="CONFIRM">http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-03.xml" source="GENTOO">GLSA-200705-03</ref>
      <ref url="http://secunia.com/advisories/33668" source="SECUNIA">33668</ref>
      <ref url="http://secunia.com/advisories/25280" source="SECUNIA">25280</ref>
      <ref url="http://secunia.com/advisories/25106" source="SECUNIA">25106</ref>
      <ref url="http://secunia.com/advisories/24732" source="SECUNIA">24732</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10643" source="OVAL">oval:org.mitre.oval:def:10643</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795" source="HP">SSRT071447</ref>
      <ref url="http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx" source="CONFIRM">http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx</ref>
      <ref url="http://www.securityfocus.com/bid/25159" source="BID">25159</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485938/100/0/threaded" source="BUGTRAQ">20080108 VMSA-2008-0002 Low severity security update for VirtualCenter and ESX Server 3.0.2, and ESX 3.0.1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0261.html" source="REDHAT">RHSA-2008:0261</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0360.html" source="REDHAT">RHSA-2007:0360</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_15_sr.html" source="SUSE">SUSE-SR:2007:015</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:241" source="MANDRIVA">MDKSA-2007:241</ref>
      <ref url="http://www.fujitsu.com/global/support/software/security/products-f/interstage-200702e.html" source="CONFIRM">http://www.fujitsu.com/global/support/software/security/products-f/interstage-200702e.html</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-206.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-206.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-239312-1" source="SUNALERT">239312</ref>
      <ref url="http://securityreason.com/securityalert/2446" source="SREASON">2446</ref>
      <ref url="http://secunia.com/advisories/30908" source="SECUNIA">30908</ref>
      <ref url="http://secunia.com/advisories/30899" source="SECUNIA">30899</ref>
      <ref url="http://secunia.com/advisories/28365" source="SECUNIA">28365</ref>
      <ref url="http://secunia.com/advisories/27037" source="SECUNIA">27037</ref>
      <ref url="http://secunia.com/advisories/26660" source="SECUNIA">26660</ref>
      <ref url="http://secunia.com/advisories/26235" source="SECUNIA">26235</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2008/000003.html" source="MLIST">[Security-announce] 20080107 VMSA-2008-0002 Low severity security update for VirtualCenter and ESX Server 3.0.2, and ESX 3.0.1</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html" source="APPLE">APPLE-SA-2007-07-31</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795" source="HP">HPSBUX02262</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=306172" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=306172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="" edition=":win32"/>
      </prod>
      <prod vendor="apache" name="tomcat">
        <vers prev="1" num="5.0.19"/>
        <vers prev="1" num="5.0.28"/>
        <vers prev="1" num="5.5.0"/>
        <vers prev="1" num="5.5.1"/>
        <vers prev="1" num="5.5.10"/>
        <vers prev="1" num="5.5.11"/>
        <vers prev="1" num="5.5.12"/>
        <vers prev="1" num="5.5.13"/>
        <vers prev="1" num="5.5.14"/>
        <vers prev="1" num="5.5.15"/>
        <vers prev="1" num="5.5.16"/>
        <vers prev="1" num="5.5.17"/>
        <vers prev="1" num="5.5.18"/>
        <vers prev="1" num="5.5.19"/>
        <vers prev="1" num="5.5.2"/>
        <vers prev="1" num="5.5.20"/>
        <vers prev="1" num="5.5.21"/>
        <vers prev="1" num="5.5.22"/>
        <vers prev="1" num="5.5.3"/>
        <vers prev="1" num="5.5.4"/>
        <vers prev="1" num="5.5.5"/>
        <vers prev="1" num="5.5.6"/>
        <vers prev="1" num="5.5.7"/>
        <vers prev="1" num="5.5.8"/>
        <vers prev="1" num="5.5.9"/>
        <vers prev="1" num="6.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0451" published="2007-02-16" name="CVE-2007-0451" modified="2011-05-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage."</descript>
    </desc>
    <sols>
      <sol source="nvd">Upgrade to SpamAssassin version 3.1.8</sol>
    </sols>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22584" source="BID" patch="1">22584</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1073" source="CONFIRM">https://issues.rpath.com/browse/RPL-1073</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32536" source="XF">spamassassin-url-dos(32536)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0628" source="VUPEN" adv="1">ADV-2007-0628</ref>
      <ref url="http://www.securitytracker.com/id?1017666" source="SECTRACK">1017666</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0075.html" source="REDHAT">RHSA-2007:0075</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_6_sr.html" source="SUSE">SUSE-SR:2007:006</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:049" source="MANDRIVA">MDKSA-2007:049</ref>
      <ref url="http://svn.apache.org/repos/asf/spamassassin/branches/3.1/build/announcements/3.1.8.txt" source="CONFIRM">http://svn.apache.org/repos/asf/spamassassin/branches/3.1/build/announcements/3.1.8.txt</ref>
      <ref url="http://spamassassin.apache.org/advisories/cve-2007-0451.txt" source="CONFIRM">http://spamassassin.apache.org/advisories/cve-2007-0451.txt</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-02.xml" source="GENTOO">GLSA-200703-02</ref>
      <ref url="http://secunia.com/advisories/24889" source="SECUNIA" adv="1">24889</ref>
      <ref url="http://secunia.com/advisories/24307" source="SECUNIA" adv="1">24307</ref>
      <ref url="http://secunia.com/advisories/24265" source="SECUNIA" adv="1">24265</ref>
      <ref url="http://secunia.com/advisories/24256" source="SECUNIA" adv="1">24256</ref>
      <ref url="http://secunia.com/advisories/24250" source="SECUNIA" adv="1">24250</ref>
      <ref url="http://secunia.com/advisories/24200" source="SECUNIA" adv="1">24200</ref>
      <ref url="http://secunia.com/advisories/24197" source="SECUNIA" adv="1">24197</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0074.html" source="REDHAT">RHSA-2007:0074</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10018" source="OVAL">oval:org.mitre.oval:def:10018</ref>
      <ref url="http://osvdb.org/33207" source="OSVDB">33207</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="spamassassin">
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.1.0"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers prev="1" num="3.1.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0452" published="2007-02-05" name="CVE-2007-0452" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:C)" CVSS_score="6.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.0" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">smbd in Samba 3.0.6 through 3.0.23d allows remote authenticated users to cause a denial of service (memory and CPU exhaustion) by renaming a file in a way that prevents a request from being removed from the deferred open queue, which triggers an infinite loop.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459167/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20070205 [SAMBA-SECURITY] CVE-2007-0452: Potential DoS against smbd in Samba 3.0.6 - 3.0.23d</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1278" source="VUPEN">ADV-2007-1278</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0483" source="VUPEN">ADV-2007-0483</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9758" source="OVAL">oval:org.mitre.oval:def:9758</ref>
      <ref url="http://osvdb.org/33100" source="OSVDB">33100</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00943462" source="HP">HPSBUX02204</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00943462" source="HP">HPSBUX02204</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1005" source="CONFIRM">https://issues.rpath.com/browse/RPL-1005</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32301" source="XF">samba-smbd-filerename-dos(32301)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-419-1" source="UBUNTU">USN-419-1</ref>
      <ref url="http://www.trustix.org/errata/2007/0007" source="TRUSTIX">2007-0007</ref>
      <ref url="http://www.securityfocus.com/bid/22395" source="BID">22395</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459365/100/0/threaded" source="BUGTRAQ">20070207 rPSA-2007-0026-1 samba samba-swat</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0061.html" source="REDHAT">RHSA-2007:0061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0060.html" source="REDHAT">RHSA-2007:0060</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:034" source="MANDRIVA">MDKSA-2007:034</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200702-01.xml" source="GENTOO">GLSA-200702-01</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1257" source="DEBIAN">DSA-1257</ref>
      <ref url="http://us1.samba.org/samba/security/CVE-2007-0452.html" source="CONFIRM">http://us1.samba.org/samba/security/CVE-2007-0452.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200588-1" source="SUNALERT">200588</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.476916" source="SLACKWARE">SSA:2007-038-01</ref>
      <ref url="http://securitytracker.com/id?1017587" source="SECTRACK">1017587</ref>
      <ref url="http://securityreason.com/securityalert/2219" source="SREASON">2219</ref>
      <ref url="http://secunia.com/advisories/24792" source="SECUNIA">24792</ref>
      <ref url="http://secunia.com/advisories/24284" source="SECUNIA">24284</ref>
      <ref url="http://secunia.com/advisories/24188" source="SECUNIA">24188</ref>
      <ref url="http://secunia.com/advisories/24151" source="SECUNIA">24151</ref>
      <ref url="http://secunia.com/advisories/24145" source="SECUNIA">24145</ref>
      <ref url="http://secunia.com/advisories/24140" source="SECUNIA">24140</ref>
      <ref url="http://secunia.com/advisories/24101" source="SECUNIA">24101</ref>
      <ref url="http://secunia.com/advisories/24076" source="SECUNIA">24076</ref>
      <ref url="http://secunia.com/advisories/24067" source="SECUNIA">24067</ref>
      <ref url="http://secunia.com/advisories/24060" source="SECUNIA">24060</ref>
      <ref url="http://secunia.com/advisories/24046" source="SECUNIA">24046</ref>
      <ref url="http://secunia.com/advisories/24030" source="SECUNIA">24030</ref>
      <ref url="http://secunia.com/advisories/24021" source="SECUNIA">24021</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Feb/0002.html" source="SUSE">SUSE-SA:2007:016</ref>
      <ref url="http://fedoranews.org/cms/node/2580" source="FEDORA">FEDORA-2007-220</ref>
      <ref url="http://fedoranews.org/cms/node/2579" source="FEDORA">FEDORA-2007-219</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc" source="SGI">20070201-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14a"/>
        <vers num="3.0.20"/>
        <vers num="3.0.20a"/>
        <vers num="3.0.20b"/>
        <vers num="3.0.21"/>
        <vers num="3.0.21a"/>
        <vers num="3.0.21b"/>
        <vers num="3.0.21c"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.23a"/>
        <vers num="3.0.23b"/>
        <vers num="3.0.23c"/>
        <vers num="3.0.23d"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0453" published="2007-02-05" name="CVE-2007-0453" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in the nss_winbind.so.1 library in Samba 3.0.21 through 3.0.23d, as used in the winbindd daemon on Solaris, allows attackers to execute arbitrary code via the (1) gethostbyname and (2) getipnodebyname functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
      <env/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459168/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20070205 [SAMBA-SECURITY] CVE-2007-0453: Buffer overrun in nss_winbind.so.1 on Solaris</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0483" source="VUPEN">ADV-2007-0483</ref>
      <ref url="http://osvdb.org/33098" source="OSVDB">33098</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1005" source="CONFIRM">https://issues.rpath.com/browse/RPL-1005</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32231" source="XF">samba-winbind-bo(32231)</ref>
      <ref url="http://www.trustix.org/errata/2007/0007" source="TRUSTIX">2007-0007</ref>
      <ref url="http://www.securityfocus.com/bid/22410" source="BID">22410</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459365/100/0/threaded" source="BUGTRAQ">20070207 rPSA-2007-0026-1 samba samba-swat</ref>
      <ref url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.012.html" source="OPENPKG">OpenPKG-SA-2007.012</ref>
      <ref url="http://us1.samba.org/samba/security/CVE-2007-0453.html" source="CONFIRM">http://us1.samba.org/samba/security/CVE-2007-0453.html</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.476916" source="SLACKWARE">SSA:2007-038-01</ref>
      <ref url="http://securitytracker.com/id?1017589" source="SECTRACK">1017589</ref>
      <ref url="http://secunia.com/advisories/24151" source="SECUNIA">24151</ref>
      <ref url="http://secunia.com/advisories/24101" source="SECUNIA">24101</ref>
      <ref url="http://secunia.com/advisories/24043" source="SECUNIA">24043</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="3.0.21"/>
        <vers num="3.0.21a"/>
        <vers num="3.0.21b"/>
        <vers num="3.0.21c"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.23a"/>
        <vers num="3.0.23b"/>
        <vers num="3.0.23c"/>
        <vers num="3.0.23d"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0454" published="2007-02-05" name="CVE-2007-0454" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 through 3.0.23d allows context-dependent attackers to execute arbitrary code via format string specifiers in a filename on an AFS file system, which is not properly handled during Windows ACL mapping.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/649732" source="CERT-VN">VU#649732</ref>
      <ref url="http://www.securityfocus.com/bid/22403" source="BID" patch="1">22403</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1005" source="CONFIRM">https://issues.rpath.com/browse/RPL-1005</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32304" source="XF">samba-afsacl-format-string(32304)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0483" source="VUPEN" adv="1">ADV-2007-0483</ref>
      <ref url="http://www.ubuntu.com/usn/usn-419-1" source="UBUNTU">USN-419-1</ref>
      <ref url="http://www.trustix.org/errata/2007/0007" source="TRUSTIX">2007-0007</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459365/100/0/threaded" source="BUGTRAQ">20070207 rPSA-2007-0026-1 samba samba-swat</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459179/100/0/threaded" source="BUGTRAQ">20070205 [SAMBA-SECURITY] CVE-2007-0454: Format string bug in afsacl.so VFS plugin</ref>
      <ref url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.012.html" source="OPENPKG">OpenPKG-SA-2007.012</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:034" source="MANDRIVA">MDKSA-2007:034</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200702-01.xml" source="GENTOO">GLSA-200702-01</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1257" source="DEBIAN">DSA-1257</ref>
      <ref url="http://us1.samba.org/samba/security/CVE-2007-0454.html" source="CONFIRM">http://us1.samba.org/samba/security/CVE-2007-0454.html</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.476916" source="SLACKWARE">SSA:2007-038-01</ref>
      <ref url="http://securitytracker.com/id?1017588" source="SECTRACK">1017588</ref>
      <ref url="http://secunia.com/advisories/24151" source="SECUNIA" adv="1">24151</ref>
      <ref url="http://secunia.com/advisories/24145" source="SECUNIA" adv="1">24145</ref>
      <ref url="http://secunia.com/advisories/24101" source="SECUNIA" adv="1">24101</ref>
      <ref url="http://secunia.com/advisories/24067" source="SECUNIA" adv="1">24067</ref>
      <ref url="http://secunia.com/advisories/24060" source="SECUNIA" adv="1">24060</ref>
      <ref url="http://secunia.com/advisories/24046" source="SECUNIA" adv="1">24046</ref>
      <ref url="http://secunia.com/advisories/24021" source="SECUNIA" adv="1">24021</ref>
      <ref url="http://osvdb.org/33101" source="OSVDB">33101</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.14a"/>
        <vers num="3.0.20"/>
        <vers num="3.0.20a"/>
        <vers num="3.0.20b"/>
        <vers num="3.0.21"/>
        <vers num="3.0.21a"/>
        <vers num="3.0.21b"/>
        <vers num="3.0.21c"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23d"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":mips"/>
        <vers num="3.0" edition=":s-390"/>
        <vers num="3.0" edition=":alpha"/>
        <vers num="3.0" edition=":mipsel"/>
        <vers num="3.0" edition=":hppa"/>
        <vers num="3.0" edition=":ia-32"/>
        <vers num="3.0" edition=":arm"/>
        <vers num="3.0" edition=":ppc"/>
        <vers num="3.0" edition=":m68k"/>
        <vers num="3.0" edition=":ia-64"/>
        <vers num="3.0" edition=":sparc"/>
        <vers num="3.1" edition=""/>
        <vers num="3.1" edition=":ia-64"/>
        <vers num="3.1" edition=":s-390"/>
        <vers num="3.1" edition=":mipsel"/>
        <vers num="3.1" edition=":hppa"/>
        <vers num="3.1" edition=":m68k"/>
        <vers num="3.1" edition=":alpha"/>
        <vers num="3.1" edition=":arm"/>
        <vers num="3.1" edition=":sparc"/>
        <vers num="3.1" edition=":ppc"/>
        <vers num="3.1" edition=":mips"/>
        <vers num="3.1" edition=":amd64"/>
        <vers num="3.1" edition=":ia-32"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="2006" edition=""/>
        <vers num="2006" edition=":x86_64"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":x86_64"/>
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":x86_64"/>
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linuxsoft_2007">
        <vers num="" edition=":x86_64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0455" published="2007-01-30" name="CVE-2007-0455" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded font.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://issues.rpath.com/browse/RPL-1268" source="CONFIRM">https://issues.rpath.com/browse/RPL-1268</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1030" source="CONFIRM">https://issues.rpath.com/browse/RPL-1030</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0022" source="VUPEN">ADV-2011-0022</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0400" source="VUPEN">ADV-2007-0400</ref>
      <ref url="http://www.trustix.org/errata/2007/0007" source="TRUSTIX">2007-0007</ref>
      <ref url="http://www.securityfocus.com/bid/22289" source="BID">22289</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466166/100/0/threaded" source="BUGTRAQ">20070418 rPSA-2007-0073-1 php php-mysql php-pgsql</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0162.html" source="REDHAT">RHSA-2007:0162</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0153.html" source="REDHAT">RHSA-2007:0153</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:038" source="MANDRIVA">MDKSA-2007:038</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:036" source="MANDRIVA">MDKSA-2007:036</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:035" source="MANDRIVA">MDKSA-2007:035</ref>
      <ref url="http://secunia.com/advisories/42813" source="SECUNIA">42813</ref>
      <ref url="http://secunia.com/advisories/24965" source="SECUNIA">24965</ref>
      <ref url="http://secunia.com/advisories/24945" source="SECUNIA">24945</ref>
      <ref url="http://secunia.com/advisories/24924" source="SECUNIA">24924</ref>
      <ref url="http://secunia.com/advisories/24151" source="SECUNIA">24151</ref>
      <ref url="http://secunia.com/advisories/24143" source="SECUNIA">24143</ref>
      <ref url="http://secunia.com/advisories/24107" source="SECUNIA">24107</ref>
      <ref url="http://secunia.com/advisories/24053" source="SECUNIA">24053</ref>
      <ref url="http://secunia.com/advisories/24052" source="SECUNIA">24052</ref>
      <ref url="http://secunia.com/advisories/24022" source="SECUNIA">24022</ref>
      <ref url="http://secunia.com/advisories/23916" source="SECUNIA" adv="1">23916</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0155.html" source="REDHAT">RHSA-2007:0155</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11303" source="OVAL">oval:org.mitre.oval:def:11303</ref>
      <ref url="http://lists.rpath.com/pipermail/security-announce/2007-February/000145.html" source="MLIST">[security-announce] 20070208 rPSA-2007-0028-1 gd</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052854.html" source="FEDORA">FEDORA-2010-19022</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052848.html" source="FEDORA">FEDORA-2010-19033</ref>
      <ref url="http://fedoranews.org/cms/node/2631" source="FEDORA">FEDORA-2007-150</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=224607" source="CONFIRM" adv="1">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=224607</ref>
      <ref url="http://www.ubuntu.com/usn/usn-473-1" source="UBUNTU">USN-473-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0146.html" source="REDHAT">RHSA-2008:0146</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:109" source="MANDRIVA">MDKSA-2007:109</ref>
      <ref url="http://secunia.com/advisories/29157" source="SECUNIA">29157</ref>
      <ref url="http://secunia.com/advisories/25575" source="SECUNIA">25575</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gd_graphics_library" name="gdlib">
        <vers num="2.0.1"/>
        <vers num="2.0.15"/>
        <vers num="2.0.20"/>
        <vers num="2.0.21"/>
        <vers num="2.0.22"/>
        <vers num="2.0.23"/>
        <vers num="2.0.26"/>
        <vers num="2.0.27"/>
        <vers num="2.0.28"/>
        <vers num="2.0.33"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0456" published="2007-02-02" name="CVE-2007-0456" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the LLT dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2007-01.html" source="CONFIRM" patch="1" adv="1">http://www.wireshark.org/security/wnpa-sec-2007-01.html</ref>
      <ref url="http://www.securityfocus.com/bid/22352" source="BID" patch="1" adv="1">22352</ref>
      <ref url="http://secunia.com/advisories/24016" source="SECUNIA" patch="1" adv="1">24016</ref>
      <ref url="https://issues.rpath.com/browse/RPL-985" source="CONFIRM">https://issues.rpath.com/browse/RPL-985</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32056" source="XF">wireshark-lltdissector-dos(32056)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0443" source="VUPEN">ADV-2007-0443</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0066.html" source="REDHAT">RHSA-2007:0066</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:033" source="MANDRIVA">MDKSA-2007:033</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm</ref>
      <ref url="http://securitytracker.com/id?1017581" source="SECTRACK">1017581</ref>
      <ref url="http://secunia.com/advisories/24970" source="SECUNIA">24970</ref>
      <ref url="http://secunia.com/advisories/24650" source="SECUNIA">24650</ref>
      <ref url="http://secunia.com/advisories/24515" source="SECUNIA">24515</ref>
      <ref url="http://secunia.com/advisories/24084" source="SECUNIA">24084</ref>
      <ref url="http://secunia.com/advisories/24025" source="SECUNIA">24025</ref>
      <ref url="http://secunia.com/advisories/24011" source="SECUNIA">24011</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14867" source="OVAL">oval:org.mitre.oval:def:14867</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11342" source="OVAL">oval:org.mitre.oval:def:11342</ref>
      <ref url="http://osvdb.org/33073" source="OSVDB">33073</ref>
      <ref url="http://fedoranews.org/cms/node/2565" source="FEDORA">FEDORA-2007-207</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" source="SGI">20070301-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="0.99.3"/>
        <vers num="0.99.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0457" published="2007-02-02" name="CVE-2007-0457" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the IEEE 802.11 dissector in Wireshark (formerly Ethereal) 0.10.14 through 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2007-01.html" source="CONFIRM" patch="1" adv="1">http://www.wireshark.org/security/wnpa-sec-2007-01.html</ref>
      <ref url="http://www.securityfocus.com/bid/22352" source="BID" patch="1" adv="1">22352</ref>
      <ref url="http://secunia.com/advisories/24016" source="SECUNIA" patch="1" adv="1">24016</ref>
      <ref url="https://issues.rpath.com/browse/RPL-985" source="CONFIRM">https://issues.rpath.com/browse/RPL-985</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32055" source="XF">wireshark-ieeedissector-dos(32055)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0443" source="VUPEN">ADV-2007-0443</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0066.html" source="REDHAT">RHSA-2007:0066</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:033" source="MANDRIVA">MDKSA-2007:033</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm</ref>
      <ref url="http://securitytracker.com/id?1017581" source="SECTRACK">1017581</ref>
      <ref url="http://secunia.com/advisories/24970" source="SECUNIA">24970</ref>
      <ref url="http://secunia.com/advisories/24650" source="SECUNIA">24650</ref>
      <ref url="http://secunia.com/advisories/24515" source="SECUNIA">24515</ref>
      <ref url="http://secunia.com/advisories/24084" source="SECUNIA">24084</ref>
      <ref url="http://secunia.com/advisories/24025" source="SECUNIA">24025</ref>
      <ref url="http://secunia.com/advisories/24011" source="SECUNIA">24011</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11003" source="OVAL">oval:org.mitre.oval:def:11003</ref>
      <ref url="http://osvdb.org/33074" source="OSVDB">33074</ref>
      <ref url="http://fedoranews.org/cms/node/2565" source="FEDORA">FEDORA-2007-207</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" source="SGI">20070301-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="0.10.14"/>
        <vers num="0.10.2"/>
        <vers num="0.10.3"/>
        <vers num="0.10.4"/>
        <vers num="0.10.5"/>
        <vers num="0.10.6"/>
        <vers num="0.10.7"/>
        <vers num="0.10.8"/>
        <vers num="0.10.9"/>
        <vers num="0.99.0"/>
        <vers num="0.99.2"/>
        <vers num="0.99.3"/>
        <vers num="0.99.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0458" published="2007-02-02" name="CVE-2007-0458" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the HTTP dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors, a different issue than CVE-2006-5468.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2007-01.html" source="CONFIRM" patch="1" adv="1">http://www.wireshark.org/security/wnpa-sec-2007-01.html</ref>
      <ref url="http://www.securityfocus.com/bid/22352" source="BID" patch="1" adv="1">22352</ref>
      <ref url="https://issues.rpath.com/browse/RPL-985" source="CONFIRM">https://issues.rpath.com/browse/RPL-985</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32054" source="XF">wireshark-httpdissector-dos(32054)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0443" source="VUPEN">ADV-2007-0443</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0066.html" source="REDHAT">RHSA-2007:0066</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:033" source="MANDRIVA">MDKSA-2007:033</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm</ref>
      <ref url="http://securitytracker.com/id?1017581" source="SECTRACK">1017581</ref>
      <ref url="http://secunia.com/advisories/24970" source="SECUNIA">24970</ref>
      <ref url="http://secunia.com/advisories/24650" source="SECUNIA">24650</ref>
      <ref url="http://secunia.com/advisories/24515" source="SECUNIA">24515</ref>
      <ref url="http://secunia.com/advisories/24084" source="SECUNIA">24084</ref>
      <ref url="http://secunia.com/advisories/24025" source="SECUNIA">24025</ref>
      <ref url="http://secunia.com/advisories/24016" source="SECUNIA" adv="1">24016</ref>
      <ref url="http://secunia.com/advisories/24011" source="SECUNIA">24011</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14836" source="OVAL">oval:org.mitre.oval:def:14836</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10966" source="OVAL">oval:org.mitre.oval:def:10966</ref>
      <ref url="http://osvdb.org/33075" source="OSVDB">33075</ref>
      <ref url="http://fedoranews.org/cms/node/2565" source="FEDORA">FEDORA-2007-207</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" source="SGI">20070301-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="0.99.3"/>
        <vers num="0.99.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0459" published="2007-02-02" name="CVE-2007-0459" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">packet-tcp.c in the TCP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.4 allows remote attackers to cause a denial of service (application crash or hang) via fragmented HTTP packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2007-01.html" source="CONFIRM" patch="1" adv="1">http://www.wireshark.org/security/wnpa-sec-2007-01.html</ref>
      <ref url="http://www.securityfocus.com/bid/22352" source="BID" patch="1" adv="1">22352</ref>
      <ref url="http://secunia.com/advisories/24016" source="SECUNIA" patch="1" adv="1">24016</ref>
      <ref url="https://issues.rpath.com/browse/RPL-985" source="CONFIRM">https://issues.rpath.com/browse/RPL-985</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32053" source="XF">wireshark-tcpdissector-dos(32053)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0443" source="VUPEN">ADV-2007-0443</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0066.html" source="REDHAT">RHSA-2007:0066</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:033" source="MANDRIVA">MDKSA-2007:033</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm</ref>
      <ref url="http://securitytracker.com/id?1017581" source="SECTRACK">1017581</ref>
      <ref url="http://secunia.com/advisories/24970" source="SECUNIA" adv="1">24970</ref>
      <ref url="http://secunia.com/advisories/24650" source="SECUNIA" adv="1">24650</ref>
      <ref url="http://secunia.com/advisories/24515" source="SECUNIA">24515</ref>
      <ref url="http://secunia.com/advisories/24084" source="SECUNIA">24084</ref>
      <ref url="http://secunia.com/advisories/24025" source="SECUNIA">24025</ref>
      <ref url="http://secunia.com/advisories/24011" source="SECUNIA">24011</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14875" source="OVAL">oval:org.mitre.oval:def:14875</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10465" source="OVAL">oval:org.mitre.oval:def:10465</ref>
      <ref url="http://fedoranews.org/cms/node/2565" source="FEDORA">FEDORA-2007-207</ref>
      <ref url="http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1200" source="MISC" adv="1">http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1200</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" source="SGI">20070301-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="0.99.2"/>
        <vers num="0.99.3"/>
        <vers num="0.99.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0460" published="2007-01-23" name="CVE-2007-0460" modified="2010-09-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in ulogd for SUSE Linux 9.3 up to 10.1, and possibly other distributions, have unknown impact and attack vectors related to "improper string length calculations."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22139" source="BID">22139</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_01_sr.html" source="SUSE" adv="1">SUSE-SR:2007:001</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:028" source="MANDRIVA">MDKSA-2007:028</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-17.xml" source="GENTOO">GLSA-200703-17</ref>
      <ref url="http://secunia.com/advisories/24524" source="SECUNIA" adv="1">24524</ref>
      <ref url="http://secunia.com/advisories/23863" source="SECUNIA" adv="1">23863</ref>
      <ref url="http://osvdb.org/32939" source="OSVDB">32939</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers prev="1" num="10.1"/>
        <vers num="9.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0461" published="2007-01-23" name="CVE-2007-0461" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple memory leaks in the Dazuko anti-virus helper module before 2.3.2 allow attackers to cause a denial of service (memory consumption) via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <other/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/2007_01_sr.html" source="SUSE" adv="1">SUSE-SR:2007:001</ref>
      <ref url="http://osvdb.org/38322" source="OSVDB">38322</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dazuko" name="dazuko">
        <vers prev="1" num="2.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0462" published="2007-01-25" name="CVE-2007-0462" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PICT image with a malformed Alpha RGB (ARGB) record, which triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0337" source="VUPEN">ADV-2007-0337</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-23-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-23-01-2007.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31698" source="XF">macos-argb-dos(31698)</ref>
      <ref url="http://www.securityfocus.com/bid/22207" source="BID">22207</ref>
      <ref url="http://www.osvdb.org/32696" source="OSVDB">32696</ref>
      <ref url="http://secunia.com/advisories/23859" source="SECUNIA">23859</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.1.3"/>
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0463" published="2007-01-29" name="CVE-2007-0463" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in Apple Software Update 2.0.5 on Mac OS X 10.4.8 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in (1) SWUTMP or (2) SUCATALOG filenames, or using the (3) application/x-apple.sucatalog+xml MIME type.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0337" source="VUPEN">ADV-2007-0337</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-24-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-24-01-2007.html</ref>
      <ref url="http://www.securitytracker.com/id?1017755" source="SECTRACK">1017755</ref>
      <ref url="http://www.securityfocus.com/bid/22222" source="BID">22222</ref>
      <ref url="http://www.osvdb.org/32703" source="OSVDB">32703</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE">APPLE-SA-2007-03-13</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="software_update">
        <vers num="2.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0464" published="2007-01-30" name="CVE-2007-0464" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The _CFNetConnectionWillEnqueueRequests function in CFNetwork 129.19 on Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (application crash) via a crafted HTTP 301 response, which results in a NULL pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-319A.html" source="CERT">TA07-319A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31837" source="XF">macos-cfnetwork-dos(31837)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3868" source="VUPEN" adv="1">ADV-2007-3868</ref>
      <ref url="http://www.securityfocus.com/bid/26444" source="BID">26444</ref>
      <ref url="http://www.securityfocus.com/bid/22249" source="BID">22249</ref>
      <ref url="http://www.osvdb.org/32704" source="OSVDB">32704</ref>
      <ref url="http://www.milw0rm.com/exploits/3200" source="MILW0RM">3200</ref>
      <ref url="http://secunia.com/advisories/27643" source="SECUNIA" adv="1">27643</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-25-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-25-01-2007.html</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.html" source="APPLE">APPLE-SA-2007-11-14</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307041" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307041</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cfnetwork" name="cfnetwork">
        <vers num="129.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0465" published="2007-01-30" name="CVE-2007-0465" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a (1) PKG, (2) DISTZ, or (3) MPKG package filename.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" source="CERT">TA07-109A</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1470" source="VUPEN">ADV-2007-1470</ref>
      <ref url="http://www.securityfocus.com/bid/22272" source="BID">22272</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-26-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-26-01-2007.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31883" source="XF">macos-installer-format-string(31883)</ref>
      <ref url="http://www.securitytracker.com/id?1017940" source="SECTRACK">1017940</ref>
      <ref url="http://www.osvdb.org/32705" source="OSVDB">32705</ref>
      <ref url="http://secunia.com/advisories/24966" source="SECUNIA">24966</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" source="APPLE">APPLE-SA-2007-04-19</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305391" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305391</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="installer">
        <vers num="2.1.5"/>
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0466" published="2007-01-30" name="CVE-2007-0466" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Telestream Flip4Mac Windows Media Components for Quicktime 2.1.0.33 allows remote attackers to execute arbitrary code via a crafted ASF_File_Properties_Object size field in a WMV file, which triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0389" source="VUPEN">ADV-2007-0389</ref>
      <ref url="http://www.securityfocus.com/bid/22286" source="BID">22286</ref>
      <ref url="http://secunia.com/advisories/23958" source="SECUNIA" adv="1">23958</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-27-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-27-01-2007.html</ref>
      <ref url="http://www.osvdb.org/32697" source="OSVDB">32697</ref>
    </refs>
    <vuln_soft>
      <prod vendor="telestream" name="flip4mac_windows_media_components_for_quicktime">
        <vers num="2.1.0.33"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0467" published="2007-01-30" name="CVE-2007-0467" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">crashdump in Apple Mac OS X 10.4.8 allows local users in the admin group to modify arbitrary files or gain privileges via a symlink attack on application logs in /Library/Logs/CrashReporter/.</descript>
      <descript source="nvd">Successful exploitation requires that the attacker is already a part of the administrator group.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/363112" source="CERT-VN">VU#363112</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31888" source="XF">macos-crashreporterd-privilege-escalation(31888)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://www.securitytracker.com/id?1017751" source="SECTRACK">1017751</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-28-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-28-01-2007.html</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
      <ref url="http://www.osvdb.org/32706" source="OSVDB">32706</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE">APPLE-SA-2007-03-13</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0468" published="2007-01-23" name="CVE-2007-0468" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in rcdll.dll in msdev.exe in Visual C++ (MSVC) in Microsoft Visual Studio 6.0 SP6 allows user-assisted remote attackers to execute arbitrary code via a long file path in the "1 TYPELIB MOVEABLE PURE" option in an RC file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0296" source="VUPEN">ADV-2007-0296</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457646/100/0/threaded" source="BUGTRAQ" adv="1">20070122 Microsoft Visual C++ (.RC) resource files buffer overflow vulnerability</ref>
      <ref url="http://www.anspi.pl/~porkythepig/visualization/rc-kupiekrowe.cpp" source="MISC">http://www.anspi.pl/~porkythepig/visualization/rc-kupiekrowe.cpp</ref>
      <ref url="http://secunia.com/advisories/23856" source="SECUNIA" adv="1">23856</ref>
      <ref url="http://osvdb.org/31607" source="OSVDB">31607</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31665" source="XF">visualstudio-rc-bo(31665)</ref>
      <ref url="http://securityreason.com/securityalert/2172" source="SREASON">2172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visual_studio">
        <vers num="6.0" edition="sp6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0469" published="2007-01-23" name="CVE-2007-0469" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The extract_files function in installer.rb in RubyGems before 0.9.1 does not check whether files exist before overwriting them, which allows user-assisted remote attackers to overwrite arbitrary files, cause a denial of service, or execute arbitrary code via crafted GEM packages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://rubyforge.org/frs/shownotes.php?release_id=9074" source="CONFIRM" patch="1" adv="1">http://rubyforge.org/frs/shownotes.php?release_id=9074</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0295" source="VUPEN">ADV-2007-0295</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31688" source="XF">rubygems-extractfiles-file-overwrite(31688)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458128/100/0/threaded" source="BUGTRAQ">20070121 RubyGems 0.9.0 and earlier installation exploit</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_4_sr.html" source="SUSE">SUSE-SR:2007:004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=116939816621060&amp;w=2" source="FULLDISC">20070121 RubyGems 0.9.0 and earlier installation exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rubyforge" name="rubygems">
        <vers num="0.8.11"/>
        <vers prev="1" num="0.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0470" published="2007-01-23" name="CVE-2007-0470" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in tip in Sun Solaris 8, 9, and 10 allow local users to gain uucp account privileges via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102773-1" source="SUNALERT" patch="1">102773</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0317" source="VUPEN">ADV-2007-0317</ref>
      <ref url="http://osvdb.org/31616" source="OSVDB">31616</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31669" source="XF">solaris-tip-privilege-escalation(31669)</ref>
      <ref url="http://www.securityfocus.com/bid/22190" source="BID">22190</ref>
      <ref url="http://securitytracker.com/id?1017546" source="SECTRACK">1017546</ref>
      <ref url="http://secunia.com/advisories/23821" source="SECUNIA">23821</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2038" source="OVAL" sig="1">oval:org.mitre.oval:def:2038</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition=""/>
        <vers num="10.0" edition=":sparc"/>
        <vers num="8.0"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0471" published="2007-01-23" name="CVE-2007-0471" modified="2011-03-07" discovered="2006-12-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">sre/params.php in the Integrity Clientless Security (ICS) component in Check Point Connectra NGX R62 3.x and earlier before Security Hotfix 5, and possibly VPN-1 NGX R62, allows remote attackers to bypass security requirements via a crafted Report parameter, which returns a valid ICSCookie authentication token.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31646" source="XF" patch="1">checkpoint-params-security-bypass(31646)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0276" source="VUPEN" adv="1">ADV-2007-0276</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457683/100/0/threaded" source="BUGTRAQ" adv="1">20070122 Check Point Connectra End Point security bypass</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457621/100/0/threaded" source="BUGTRAQ">20070122 Re: [Full-disclosure] Check Point Connectra End Point security bypass</ref>
      <ref url="http://www.checkpoint.com/downloads/latest/hfa/vpn1_security/vpn1_R62_Windows.html" source="MISC">http://www.checkpoint.com/downloads/latest/hfa/vpn1_security/vpn1_R62_Windows.html</ref>
      <ref url="http://www.checkpoint.com/downloads/latest/hfa/connectra/security_r62.html" source="CONFIRM">http://www.checkpoint.com/downloads/latest/hfa/connectra/security_r62.html</ref>
      <ref url="http://updates.checkpoint.com/fileserver/ID/7126/FILE/VPN-1_Hotfix1.pdf" source="MISC">http://updates.checkpoint.com/fileserver/ID/7126/FILE/VPN-1_Hotfix1.pdf</ref>
      <ref url="http://securitytracker.com/id?1017560" source="SECTRACK">1017560</ref>
      <ref url="http://securitytracker.com/id?1017559" source="SECTRACK">1017559</ref>
      <ref url="http://securityreason.com/securityalert/2179" source="SREASON">2179</ref>
      <ref url="http://secunia.com/advisories/23847" source="SECUNIA" adv="1">23847</ref>
      <ref url="http://osvdb.org/31655" source="OSVDB">31655</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051920.html" source="FULLDISC" adv="1">20070122 Check Point Connectra End Point security bypass</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="connectra_ngx">
        <vers prev="1" num="r62"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0472" published="2007-02-03" name="CVE-2007-0472" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Multiple race conditions in Smb4K before 0.8.0 allow local users to (1) modify arbitrary files via unspecified manipulations of Smb4K's lock file, which is not properly handled by the remove_lock_file function in core/smb4kfileio.cpp, and (2) add lines to the sudoers file via a symlink attack on temporary files, which isn't properly handled by the writeFile function in core/smb4kfileio.cpp.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <race/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html" source="MLIST" patch="1">[smb4k-announce] 20061221 Smb4K 0.8.0 and security fixes released</ref>
      <ref url="http://secunia.com/advisories/23937" source="SECUNIA" patch="1" adv="1">23937</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0393" source="VUPEN">ADV-2007-0393</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?release_id=9777" source="CONFIRM">http://developer.berlios.de/project/shownotes.php?release_id=9777</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?release_id=11902" source="CONFIRM">http://developer.berlios.de/project/shownotes.php?release_id=11902</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?release_id=11706" source="CONFIRM">http://developer.berlios.de/project/shownotes.php?release_id=11706</ref>
      <ref url="http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9630&amp;group_id=769" source="CONFIRM">http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9630&amp;group_id=769</ref>
      <ref url="http://www.securityfocus.com/bid/22299" source="BID">22299</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:042" source="MANDRIVA">MDKSA-2007:042</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml" source="GENTOO">GLSA-200703-09</ref>
      <ref url="http://secunia.com/advisories/24469" source="SECUNIA">24469</ref>
      <ref url="http://secunia.com/advisories/24111" source="SECUNIA">24111</ref>
      <ref url="http://secunia.com/advisories/23984" source="SECUNIA">23984</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html" source="SUSE">SUSE-SR:2007:002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smb4k" name="smb4k">
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0473" published="2007-02-03" name="CVE-2007-0473" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">The writeFile function in core/smb4kfileio.cpp in Smb4K before 0.8.0 does not preserve /etc/sudoers permissions across modifications, which allows local users to obtain sensitive information (/etc/sudoers contents) by reading this file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html" source="MLIST" patch="1">[smb4k-announce] 20061221 Smb4K 0.8.0 and security fixes released</ref>
      <ref url="http://secunia.com/advisories/23937" source="SECUNIA" patch="1" adv="1">23937</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0393" source="VUPEN">ADV-2007-0393</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?release_id=9777" source="CONFIRM">http://developer.berlios.de/project/shownotes.php?release_id=9777</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?release_id=11902" source="CONFIRM">http://developer.berlios.de/project/shownotes.php?release_id=11902</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?release_id=11706" source="CONFIRM">http://developer.berlios.de/project/shownotes.php?release_id=11706</ref>
      <ref url="http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9630&amp;group_id=769" source="CONFIRM">http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9630&amp;group_id=769</ref>
      <ref url="http://www.securityfocus.com/bid/22299" source="BID">22299</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:042" source="MANDRIVA">MDKSA-2007:042</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml" source="GENTOO">GLSA-200703-09</ref>
      <ref url="http://secunia.com/advisories/24469" source="SECUNIA">24469</ref>
      <ref url="http://secunia.com/advisories/24111" source="SECUNIA">24111</ref>
      <ref url="http://secunia.com/advisories/23984" source="SECUNIA">23984</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html" source="SUSE">SUSE-SR:2007:002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smb4k" name="smb4k">
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0474" published="2007-02-03" name="CVE-2007-0474" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="3.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.4" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">Smb4K before 0.8.0 allow local users, when present on the Smb4K sudoers list, to kill arbitrary processes, related to a "design issue with smb4k_kill."</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html" source="MLIST" patch="1">[smb4k-announce] 20061221 Smb4K 0.8.0 and security fixes released</ref>
      <ref url="http://secunia.com/advisories/23937" source="SECUNIA" patch="1" adv="1">23937</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0393" source="VUPEN">ADV-2007-0393</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?release_id=9777" source="CONFIRM">http://developer.berlios.de/project/shownotes.php?release_id=9777</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?release_id=11902" source="CONFIRM">http://developer.berlios.de/project/shownotes.php?release_id=11902</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?release_id=11706" source="CONFIRM">http://developer.berlios.de/project/shownotes.php?release_id=11706</ref>
      <ref url="http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9631&amp;group_id=769" source="CONFIRM">http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9631&amp;group_id=769</ref>
      <ref url="http://www.securityfocus.com/bid/22299" source="BID">22299</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:042" source="MANDRIVA">MDKSA-2007:042</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml" source="GENTOO">GLSA-200703-09</ref>
      <ref url="http://secunia.com/advisories/24469" source="SECUNIA">24469</ref>
      <ref url="http://secunia.com/advisories/24111" source="SECUNIA">24111</ref>
      <ref url="http://secunia.com/advisories/23984" source="SECUNIA">23984</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html" source="SUSE">SUSE-SR:2007:002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smb4k" name="smb4k">
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0475" published="2007-02-03" name="CVE-2007-0475" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in utilities/smb4k_*.cpp in Smb4K before 0.8.0 allow local users, when present on the Smb4K sudoers list, to gain privileges via unspecified vectors related to the args variable and unspecified other variables, in conjunction with the sudo configuration.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html" source="MLIST" patch="1">[smb4k-announce] 20061221 Smb4K 0.8.0 and security fixes released</ref>
      <ref url="http://secunia.com/advisories/23937" source="SECUNIA" patch="1" adv="1">23937</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0393" source="VUPEN">ADV-2007-0393</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?release_id=9777" source="CONFIRM">http://developer.berlios.de/project/shownotes.php?release_id=9777</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?release_id=11902" source="CONFIRM">http://developer.berlios.de/project/shownotes.php?release_id=11902</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?release_id=11706" source="CONFIRM">http://developer.berlios.de/project/shownotes.php?release_id=11706</ref>
      <ref url="http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9631&amp;group_id=769" source="CONFIRM">http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9631&amp;group_id=769</ref>
      <ref url="http://www.securityfocus.com/bid/22299" source="BID">22299</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:042" source="MANDRIVA">MDKSA-2007:042</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml" source="GENTOO">GLSA-200703-09</ref>
      <ref url="http://secunia.com/advisories/24469" source="SECUNIA">24469</ref>
      <ref url="http://secunia.com/advisories/24111" source="SECUNIA">24111</ref>
      <ref url="http://secunia.com/advisories/23984" source="SECUNIA">23984</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html" source="SUSE">SUSE-SR:2007:002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smb4k" name="smb4k">
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0476" published="2007-01-24" name="CVE-2007-0476" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The gencert.sh script, when installing OpenLDAP before 2.1.30-r10, 2.2.x before 2.2.28-r7, and 2.3.x before 2.3.30-r2 as an ebuild in Gentoo Linux, does not create temporary directories in /tmp securely during emerge, which allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0305" source="VUPEN">ADV-2007-0305</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200701-19.xml" source="GENTOO">GLSA-200701-19</ref>
      <ref url="http://secunia.com/advisories/23881" source="SECUNIA" adv="1">23881</ref>
      <ref url="http://osvdb.org/31617" source="OSVDB">31617</ref>
      <ref url="http://www.securityfocus.com/bid/22195" source="BID">22195</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gentoo" name="linux">
        <vers num="2.1.30" edition="r9"/>
        <vers num="2.2.28" edition="r7"/>
        <vers num="2.3.30" edition="r2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0477" published="2007-01-24" name="CVE-2007-0477" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Openads 2.0.x before 2.0.10, 2.3 before 2.3.31 (aka Max Media Manager before 0.3.31-alpha-pr2), and phpAdsNew/phpPgAds before 2.0.9-pr1 allows remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter in admin-search.php and (2) affiliate-search.php. NOTE: this issue may overlap CVE-2007-0363.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://developer.openads.org/browser/branches/max/trunk/CHANGELOG.txt?format=raw" source="CONFIRM">https://developer.openads.org/browser/branches/max/trunk/CHANGELOG.txt?format=raw</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0315" source="VUPEN">ADV-2007-0315</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458296/100/100/threaded" source="BUGTRAQ">20070127 Re: [OPENADS-SA-2007-002] Max Media Manager v0.1.29 and v0.3.30 vulnerability fixed</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458197/100/100/threaded" source="BUGTRAQ">20070126 [OPENADS-SA-2007-002] Max Media Manager v0.1.29 and v0.3.30 vulnerability fixed</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457990/100/200/threaded" source="BUGTRAQ">20070124 [OPENADS-SA-2007-001] phpAdsNew and phpPgAds 2.0.9-pr1 vulnerability fixed</ref>
      <ref url="http://osvdb.org/32926" source="OSVDB">32926</ref>
      <ref url="http://jvn.jp/jp/JVN%2307274813/index.html" source="JVN">JVN#07274813</ref>
      <ref url="http://forum.openads.org/index.php?showtopic=503412651" source="MISC">http://forum.openads.org/index.php?showtopic=503412651</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openads" name="openads">
        <vers num="2.3.30"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0478" published="2007-01-24" name="CVE-2007-0478" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">WebCore on Apple Mac OS X 10.3.9 and 10.4.10, as used in Safari, does not properly parse HTML comments in TITLE elements, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within an HTML comment.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31846" source="XF">safari-html-xss(31846)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31846" source="XF">safari-html-xss(31846)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2732" source="VUPEN">ADV-2007-2732</ref>
      <ref url="http://www.securityfocus.com/bid/25159" source="BID">25159</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457763/100/0/threaded" source="BUGTRAQ">20070123 Safari Improperly Parses HTML Documents &amp; BlogSpot XSS vulnerability</ref>
      <ref url="http://www.beanfuzz.com/wordpress/?p=99" source="MISC">http://www.beanfuzz.com/wordpress/?p=99</ref>
      <ref url="http://securitytracker.com/id?1018494" source="SECTRACK">1018494</ref>
      <ref url="http://secunia.com/advisories/26235" source="SECUNIA" adv="1">26235</ref>
      <ref url="http://secunia.com/advisories/23893" source="SECUNIA" adv="1">23893</ref>
      <ref url="http://osvdb.org/32712" source="OSVDB">32712</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html" source="APPLE">APPLE-SA-2007-07-31</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=306172" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=306172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num=""/>
      </prod>
      <prod vendor="apple" name="webcore">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0479" published="2007-01-24" name="CVE-2007-0479" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Memory leak in the TCP listener in Cisco IOS 9.x, 10.x, 11.x, and 12.x allows remote attackers to cause a denial of service by sending crafted TCP traffic to an IPv4 address on the IOS device.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/217912" source="CERT-VN">VU#217912</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-024A.html" source="CERT">TA07-024A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31716" source="XF">cisco-tcp-ipv4-dos(31716)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0329" source="VUPEN">ADV-2007-0329</ref>
      <ref url="http://www.securityfocus.com/bid/22208" source="BID">22208</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807cb0e4.shtml" source="CISCO">20070124 Crafted TCP Packet Can Cause Denial of Service</ref>
      <ref url="http://securitytracker.com/id?1017551" source="SECTRACK">1017551</ref>
      <ref url="http://secunia.com/advisories/23867" source="SECUNIA">23867</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5080" source="OVAL">oval:org.mitre.oval:def:5080</ref>
      <ref url="http://osvdb.org/32093" source="OSVDB">32093</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios_transmission_control_protocol">
        <vers num="12"/>
        <vers num="12.0da"/>
        <vers num="12.0db"/>
        <vers num="12.0dc"/>
        <vers num="12.0s"/>
        <vers num="12.0sc"/>
        <vers num="12.0sl"/>
        <vers num="12.0sp"/>
        <vers num="12.0st"/>
        <vers num="12.0sx"/>
        <vers num="12.0sy"/>
        <vers num="12.0sz"/>
        <vers num="12.0t"/>
        <vers num="12.0w"/>
        <vers num="12.0wc"/>
        <vers num="12.0wt"/>
        <vers num="12.0xa"/>
        <vers num="12.0xb"/>
        <vers num="12.0xc"/>
        <vers num="12.0xd"/>
        <vers num="12.0xe"/>
        <vers num="12.0xf"/>
        <vers num="12.0xg"/>
        <vers num="12.0xh"/>
        <vers num="12.0xi"/>
        <vers num="12.0xj"/>
        <vers num="12.0xk"/>
        <vers num="12.0xl"/>
        <vers num="12.0xm"/>
        <vers num="12.0xq"/>
        <vers num="12.0xr"/>
        <vers num="12.0xs"/>
        <vers num="12.0xv"/>
        <vers num="12.0xw"/>
        <vers num="12.1"/>
        <vers num="12.1aa"/>
        <vers num="12.1ax"/>
        <vers num="12.1ay"/>
        <vers num="12.1az"/>
        <vers num="12.1cx"/>
        <vers num="12.1da"/>
        <vers num="12.1db"/>
        <vers num="12.1dc"/>
        <vers num="12.1e"/>
        <vers num="12.1ea"/>
        <vers num="12.1eb"/>
        <vers num="12.1ec"/>
        <vers num="12.1eo"/>
        <vers num="12.1eu"/>
        <vers num="12.1ev"/>
        <vers num="12.1ew"/>
        <vers num="12.1ex"/>
        <vers num="12.1ey"/>
        <vers num="12.1ez"/>
        <vers num="12.1t"/>
        <vers num="12.1x"/>
        <vers num="12.1xa"/>
        <vers num="12.1xb"/>
        <vers num="12.1xc"/>
        <vers num="12.1xd"/>
        <vers num="12.1xe"/>
        <vers num="12.1xf"/>
        <vers num="12.1xg"/>
        <vers num="12.1xh"/>
        <vers num="12.1xi"/>
        <vers num="12.1xj"/>
        <vers num="12.1xl"/>
        <vers num="12.1xp"/>
        <vers num="12.1xq"/>
        <vers num="12.1xr"/>
        <vers num="12.1xs"/>
        <vers num="12.1xt"/>
        <vers num="12.1xu"/>
        <vers num="12.1xv"/>
        <vers num="12.1xw"/>
        <vers num="12.1xx"/>
        <vers num="12.1xy"/>
        <vers num="12.1xz"/>
        <vers num="12.1ya"/>
        <vers num="12.1yb"/>
        <vers num="12.1yc"/>
        <vers num="12.1yd"/>
        <vers num="12.1ye"/>
        <vers num="12.1yf"/>
        <vers num="12.1yh"/>
        <vers num="12.1yi"/>
        <vers num="12.1yj"/>
        <vers num="12.2"/>
        <vers num="12.2b"/>
        <vers num="12.2bc"/>
        <vers num="12.2bw"/>
        <vers num="12.2by"/>
        <vers num="12.2bz"/>
        <vers num="12.2cx"/>
        <vers num="12.2cy"/>
        <vers num="12.2cz"/>
        <vers num="12.2da"/>
        <vers num="12.2dd"/>
        <vers num="12.2dx"/>
        <vers num="12.2eu"/>
        <vers num="12.2ew"/>
        <vers num="12.2ewa"/>
        <vers num="12.2ex"/>
        <vers num="12.2ey"/>
        <vers num="12.2ez"/>
        <vers num="12.2fx"/>
        <vers num="12.2fy"/>
        <vers num="12.2fz"/>
        <vers num="12.2ixa"/>
        <vers num="12.2ixb"/>
        <vers num="12.2ixc"/>
        <vers num="12.2ja"/>
        <vers num="12.2jk"/>
        <vers num="12.2mb"/>
        <vers num="12.2mc"/>
        <vers num="12.2s"/>
        <vers num="12.2sb"/>
        <vers num="12.2sbc"/>
        <vers num="12.2se"/>
        <vers num="12.2sea"/>
        <vers num="12.2seb"/>
        <vers num="12.2sec"/>
        <vers num="12.2sed"/>
        <vers num="12.2see"/>
        <vers num="12.2sef"/>
        <vers num="12.2seg"/>
        <vers num="12.2sg"/>
        <vers num="12.2sga"/>
        <vers num="12.2so"/>
        <vers num="12.2sra"/>
        <vers num="12.2srb"/>
        <vers num="12.2su"/>
        <vers num="12.2sv"/>
        <vers num="12.2sw"/>
        <vers num="12.2sx"/>
        <vers num="12.2sxa"/>
        <vers num="12.2sxb"/>
        <vers num="12.2sxd"/>
        <vers num="12.2sxe"/>
        <vers num="12.2sxf"/>
        <vers num="12.2sy"/>
        <vers num="12.2sz"/>
        <vers num="12.2t"/>
        <vers num="12.2tpc"/>
        <vers num="12.2xa"/>
        <vers num="12.2xb"/>
        <vers num="12.2xc"/>
        <vers num="12.2xd"/>
        <vers num="12.2xe"/>
        <vers num="12.2xf"/>
        <vers num="12.2xg"/>
        <vers num="12.2xh"/>
        <vers num="12.2xi"/>
        <vers num="12.2xj"/>
        <vers num="12.2xk"/>
        <vers num="12.2xl"/>
        <vers num="12.2xm"/>
        <vers num="12.2xn"/>
        <vers num="12.2xq"/>
        <vers num="12.2xr"/>
        <vers num="12.2xs"/>
        <vers num="12.2xt"/>
        <vers num="12.2xu"/>
        <vers num="12.2xv"/>
        <vers num="12.2xw"/>
        <vers num="12.2ya"/>
        <vers num="12.2yb"/>
        <vers num="12.2yc"/>
        <vers num="12.2yd"/>
        <vers num="12.2ye"/>
        <vers num="12.2yf"/>
        <vers num="12.2yg"/>
        <vers num="12.2yh"/>
        <vers num="12.2yj"/>
        <vers num="12.2yk"/>
        <vers num="12.2yl"/>
        <vers num="12.2ym"/>
        <vers num="12.2yn"/>
        <vers num="12.2yo"/>
        <vers num="12.2yp"/>
        <vers num="12.2yq"/>
        <vers num="12.2yr"/>
        <vers num="12.2ys"/>
        <vers num="12.2yt"/>
        <vers num="12.2yu"/>
        <vers num="12.2yv"/>
        <vers num="12.2yw"/>
        <vers num="12.2yx"/>
        <vers num="12.2yy"/>
        <vers num="12.2yz"/>
        <vers num="12.2za"/>
        <vers num="12.2zb"/>
        <vers num="12.2zc"/>
        <vers num="12.2zd"/>
        <vers num="12.2ze"/>
        <vers num="12.2zf"/>
        <vers num="12.2zg"/>
        <vers num="12.2zh"/>
        <vers num="12.2zj"/>
        <vers num="12.2zl"/>
        <vers num="12.2zn"/>
        <vers num="12.2zp"/>
        <vers num="12.3"/>
        <vers num="12.3b"/>
        <vers num="12.3bc"/>
        <vers num="12.3bw"/>
        <vers num="12.3ja"/>
        <vers num="12.3jea"/>
        <vers num="12.3jeb"/>
        <vers num="12.3jk"/>
        <vers num="12.3jx"/>
        <vers num="12.3t"/>
        <vers num="12.3tpc"/>
        <vers num="12.3xa"/>
        <vers num="12.3xb"/>
        <vers num="12.3xc"/>
        <vers num="12.3xd"/>
        <vers num="12.3xe"/>
        <vers num="12.3xf"/>
        <vers num="12.3xg"/>
        <vers num="12.3xh"/>
        <vers num="12.3xi"/>
        <vers num="12.3xj"/>
        <vers num="12.3xk"/>
        <vers num="12.3xq"/>
        <vers num="12.3xr"/>
        <vers num="12.3xs"/>
        <vers num="12.3xu"/>
        <vers num="12.3xw"/>
        <vers num="12.3xx"/>
        <vers num="12.3xy"/>
        <vers num="12.3ya"/>
        <vers num="12.3yd"/>
        <vers num="12.3yf"/>
        <vers num="12.3yg"/>
        <vers num="12.3yh"/>
        <vers num="12.3yi"/>
        <vers num="12.3yj"/>
        <vers num="12.3yk"/>
        <vers num="12.3ym"/>
        <vers num="12.3yq"/>
        <vers num="12.3ys"/>
        <vers num="12.3yt"/>
        <vers num="12.3yu"/>
        <vers num="12.3yx"/>
        <vers num="12.3yz"/>
        <vers num="12.4"/>
        <vers num="12.4mr"/>
        <vers num="12.4sw"/>
        <vers num="12.4t"/>
        <vers num="12.4xa"/>
        <vers num="12.4xb"/>
        <vers num="12.4xc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0480" published="2007-01-24" name="CVE-2007-0480" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Cisco IOS 9.x, 10.x, 11.x, and 12.x and IOS XR 2.0.x, 3.0.x, and 3.2.x allows remote attackers to cause a denial of service or execute arbitrary code via a crafted IP option in the IP header in a (1) ICMP, (2) PIMv2, (3) PGM, or (4) URD packet.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/341288" source="CERT-VN">VU#341288</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-024A.html" source="CERT">TA07-024A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31725" source="XF">cisco-ip-option-code-execution(31725)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0329" source="VUPEN">ADV-2007-0329</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807cb157.shtml" source="CISCO" adv="1">20070124 Crafted IP Option Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1017555" source="SECTRACK">1017555</ref>
      <ref url="http://secunia.com/advisories/23867" source="SECUNIA">23867</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5666" source="OVAL">oval:org.mitre.oval:def:5666</ref>
      <ref url="http://osvdb.org/32092" source="OSVDB">32092</ref>
      <ref url="http://www.securityfocus.com/bid/22211" source="BID">22211</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios_transmission_control_protocol">
        <vers num="12"/>
        <vers num="12.0da"/>
        <vers num="12.0db"/>
        <vers num="12.0dc"/>
        <vers num="12.0s"/>
        <vers num="12.0sc"/>
        <vers num="12.0sl"/>
        <vers num="12.0sp"/>
        <vers num="12.0st"/>
        <vers num="12.0sx"/>
        <vers num="12.0sy"/>
        <vers num="12.0sz"/>
        <vers num="12.0t"/>
        <vers num="12.0w"/>
        <vers num="12.0wc"/>
        <vers num="12.0wt"/>
        <vers num="12.0xa"/>
        <vers num="12.0xb"/>
        <vers num="12.0xc"/>
        <vers num="12.0xd"/>
        <vers num="12.0xe"/>
        <vers num="12.0xf"/>
        <vers num="12.0xg"/>
        <vers num="12.0xh"/>
        <vers num="12.0xi"/>
        <vers num="12.0xj"/>
        <vers num="12.0xk"/>
        <vers num="12.0xl"/>
        <vers num="12.0xm"/>
        <vers num="12.0xq"/>
        <vers num="12.0xr"/>
        <vers num="12.0xs"/>
        <vers num="12.0xv"/>
        <vers num="12.0xw"/>
        <vers num="12.1"/>
        <vers num="12.1aa"/>
        <vers num="12.1ax"/>
        <vers num="12.1ay"/>
        <vers num="12.1az"/>
        <vers num="12.1cx"/>
        <vers num="12.1da"/>
        <vers num="12.1db"/>
        <vers num="12.1dc"/>
        <vers num="12.1e"/>
        <vers num="12.1ea"/>
        <vers num="12.1eb"/>
        <vers num="12.1ec"/>
        <vers num="12.1eo"/>
        <vers num="12.1eu"/>
        <vers num="12.1ev"/>
        <vers num="12.1ew"/>
        <vers num="12.1ex"/>
        <vers num="12.1ey"/>
        <vers num="12.1ez"/>
        <vers num="12.1t"/>
        <vers num="12.1x"/>
        <vers num="12.1xa"/>
        <vers num="12.1xb"/>
        <vers num="12.1xc"/>
        <vers num="12.1xd"/>
        <vers num="12.1xe"/>
        <vers num="12.1xf"/>
        <vers num="12.1xg"/>
        <vers num="12.1xh"/>
        <vers num="12.1xi"/>
        <vers num="12.1xj"/>
        <vers num="12.1xl"/>
        <vers num="12.1xp"/>
        <vers num="12.1xq"/>
        <vers num="12.1xr"/>
        <vers num="12.1xs"/>
        <vers num="12.1xt"/>
        <vers num="12.1xu"/>
        <vers num="12.1xv"/>
        <vers num="12.1xw"/>
        <vers num="12.1xx"/>
        <vers num="12.1xy"/>
        <vers num="12.1xz"/>
        <vers num="12.1ya"/>
        <vers num="12.1yb"/>
        <vers num="12.1yc"/>
        <vers num="12.1yd"/>
        <vers num="12.1ye"/>
        <vers num="12.1yf"/>
        <vers num="12.1yh"/>
        <vers num="12.1yi"/>
        <vers num="12.1yj"/>
        <vers num="12.2"/>
        <vers num="12.2b"/>
        <vers num="12.2bc"/>
        <vers num="12.2bw"/>
        <vers num="12.2by"/>
        <vers num="12.2bz"/>
        <vers num="12.2cx"/>
        <vers num="12.2cy"/>
        <vers num="12.2cz"/>
        <vers num="12.2da"/>
        <vers num="12.2dd"/>
        <vers num="12.2dx"/>
        <vers num="12.2eu"/>
        <vers num="12.2ew"/>
        <vers num="12.2ewa"/>
        <vers num="12.2ex"/>
        <vers num="12.2ey"/>
        <vers num="12.2ez"/>
        <vers num="12.2fx"/>
        <vers num="12.2fy"/>
        <vers num="12.2fz"/>
        <vers num="12.2ixa"/>
        <vers num="12.2ixb"/>
        <vers num="12.2ixc"/>
        <vers num="12.2ja"/>
        <vers num="12.2jk"/>
        <vers num="12.2mb"/>
        <vers num="12.2mc"/>
        <vers num="12.2s"/>
        <vers num="12.2sb"/>
        <vers num="12.2sbc"/>
        <vers num="12.2se"/>
        <vers num="12.2sea"/>
        <vers num="12.2seb"/>
        <vers num="12.2sec"/>
        <vers num="12.2sed"/>
        <vers num="12.2see"/>
        <vers num="12.2sef"/>
        <vers num="12.2seg"/>
        <vers num="12.2sg"/>
        <vers num="12.2sga"/>
        <vers num="12.2so"/>
        <vers num="12.2sra"/>
        <vers num="12.2srb"/>
        <vers num="12.2su"/>
        <vers num="12.2sv"/>
        <vers num="12.2sw"/>
        <vers num="12.2sx"/>
        <vers num="12.2sxa"/>
        <vers num="12.2sxb"/>
        <vers num="12.2sxd"/>
        <vers num="12.2sxe"/>
        <vers num="12.2sxf"/>
        <vers num="12.2sy"/>
        <vers num="12.2sz"/>
        <vers num="12.2t"/>
        <vers num="12.2tpc"/>
        <vers num="12.2xa"/>
        <vers num="12.2xb"/>
        <vers num="12.2xc"/>
        <vers num="12.2xd"/>
        <vers num="12.2xe"/>
        <vers num="12.2xf"/>
        <vers num="12.2xg"/>
        <vers num="12.2xh"/>
        <vers num="12.2xi"/>
        <vers num="12.2xj"/>
        <vers num="12.2xk"/>
        <vers num="12.2xl"/>
        <vers num="12.2xm"/>
        <vers num="12.2xn"/>
        <vers num="12.2xq"/>
        <vers num="12.2xr"/>
        <vers num="12.2xs"/>
        <vers num="12.2xt"/>
        <vers num="12.2xu"/>
        <vers num="12.2xv"/>
        <vers num="12.2xw"/>
        <vers num="12.2ya"/>
        <vers num="12.2yb"/>
        <vers num="12.2yc"/>
        <vers num="12.2yd"/>
        <vers num="12.2ye"/>
        <vers num="12.2yf"/>
        <vers num="12.2yg"/>
        <vers num="12.2yh"/>
        <vers num="12.2yj"/>
        <vers num="12.2yk"/>
        <vers num="12.2yl"/>
        <vers num="12.2ym"/>
        <vers num="12.2yn"/>
        <vers num="12.2yo"/>
        <vers num="12.2yp"/>
        <vers num="12.2yq"/>
        <vers num="12.2yr"/>
        <vers num="12.2ys"/>
        <vers num="12.2yt"/>
        <vers num="12.2yu"/>
        <vers num="12.2yv"/>
        <vers num="12.2yw"/>
        <vers num="12.2yx"/>
        <vers num="12.2yy"/>
        <vers num="12.2yz"/>
        <vers num="12.2za"/>
        <vers num="12.2zb"/>
        <vers num="12.2zc"/>
        <vers num="12.2zd"/>
        <vers num="12.2ze"/>
        <vers num="12.2zf"/>
        <vers num="12.2zg"/>
        <vers num="12.2zh"/>
        <vers num="12.2zj"/>
        <vers num="12.2zl"/>
        <vers num="12.2zn"/>
        <vers num="12.2zp"/>
        <vers num="12.3"/>
        <vers num="12.3b"/>
        <vers num="12.3bc"/>
        <vers num="12.3bw"/>
        <vers num="12.3ja"/>
        <vers num="12.3jea"/>
        <vers num="12.3jeb"/>
        <vers num="12.3jk"/>
        <vers num="12.3jx"/>
        <vers num="12.3t"/>
        <vers num="12.3tpc"/>
        <vers num="12.3xa"/>
        <vers num="12.3xb"/>
        <vers num="12.3xc"/>
        <vers num="12.3xd"/>
        <vers num="12.3xe"/>
        <vers num="12.3xf"/>
        <vers num="12.3xg"/>
        <vers num="12.3xh"/>
        <vers num="12.3xi"/>
        <vers num="12.3xj"/>
        <vers num="12.3xk"/>
        <vers num="12.3xq"/>
        <vers num="12.3xr"/>
        <vers num="12.3xs"/>
        <vers num="12.3xu"/>
        <vers num="12.3xw"/>
        <vers num="12.3xx"/>
        <vers num="12.3xy"/>
        <vers num="12.3ya"/>
        <vers num="12.3yd"/>
        <vers num="12.3yf"/>
        <vers num="12.3yg"/>
        <vers num="12.3yh"/>
        <vers num="12.3yi"/>
        <vers num="12.3yj"/>
        <vers num="12.3yk"/>
        <vers num="12.3ym"/>
        <vers num="12.3yq"/>
        <vers num="12.3ys"/>
        <vers num="12.3yt"/>
        <vers num="12.3yu"/>
        <vers num="12.3yx"/>
        <vers num="12.3yz"/>
        <vers num="12.4"/>
        <vers num="12.4mr"/>
        <vers num="12.4sw"/>
        <vers num="12.4t"/>
        <vers num="12.4xa"/>
        <vers num="12.4xb"/>
        <vers num="12.4xc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0481" published="2007-01-24" name="CVE-2007-0481" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco IOS allows remote attackers to cause a denial of service (crash) via a crafted IPv6 Type 0 Routing header.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/274760" source="CERT-VN">VU#274760</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-024A.html" source="CERT">TA07-024A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31715" source="XF">cisco-ios-ipv6-type0-dos(31715)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0329" source="VUPEN">ADV-2007-0329</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807cb0fd.shtml" source="CISCO">20070124 IPv6 Routing Header Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1017550" source="SECTRACK">1017550</ref>
      <ref url="http://secunia.com/advisories/23867" source="SECUNIA">23867</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5857" source="OVAL">oval:org.mitre.oval:def:5857</ref>
      <ref url="http://osvdb.org/32091" source="OSVDB">32091</ref>
      <ref url="http://www.securityfocus.com/bid/22210" source="BID">22210</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios_transmission_control_protocol">
        <vers num="12"/>
        <vers num="12.0da"/>
        <vers num="12.0db"/>
        <vers num="12.0dc"/>
        <vers num="12.0s"/>
        <vers num="12.0sc"/>
        <vers num="12.0sl"/>
        <vers num="12.0sp"/>
        <vers num="12.0st"/>
        <vers num="12.0sx"/>
        <vers num="12.0sy"/>
        <vers num="12.0sz"/>
        <vers num="12.0t"/>
        <vers num="12.0w"/>
        <vers num="12.0wc"/>
        <vers num="12.0wt"/>
        <vers num="12.0xa"/>
        <vers num="12.0xb"/>
        <vers num="12.0xc"/>
        <vers num="12.0xd"/>
        <vers num="12.0xe"/>
        <vers num="12.0xf"/>
        <vers num="12.0xg"/>
        <vers num="12.0xh"/>
        <vers num="12.0xi"/>
        <vers num="12.0xj"/>
        <vers num="12.0xk"/>
        <vers num="12.0xl"/>
        <vers num="12.0xm"/>
        <vers num="12.0xq"/>
        <vers num="12.0xr"/>
        <vers num="12.0xs"/>
        <vers num="12.0xv"/>
        <vers num="12.0xw"/>
        <vers num="12.1"/>
        <vers num="12.1aa"/>
        <vers num="12.1ax"/>
        <vers num="12.1ay"/>
        <vers num="12.1az"/>
        <vers num="12.1cx"/>
        <vers num="12.1da"/>
        <vers num="12.1db"/>
        <vers num="12.1dc"/>
        <vers num="12.1e"/>
        <vers num="12.1ea"/>
        <vers num="12.1eb"/>
        <vers num="12.1ec"/>
        <vers num="12.1eo"/>
        <vers num="12.1eu"/>
        <vers num="12.1ev"/>
        <vers num="12.1ew"/>
        <vers num="12.1ex"/>
        <vers num="12.1ey"/>
        <vers num="12.1ez"/>
        <vers num="12.1t"/>
        <vers num="12.1x"/>
        <vers num="12.1xa"/>
        <vers num="12.1xb"/>
        <vers num="12.1xc"/>
        <vers num="12.1xd"/>
        <vers num="12.1xe"/>
        <vers num="12.1xf"/>
        <vers num="12.1xg"/>
        <vers num="12.1xh"/>
        <vers num="12.1xi"/>
        <vers num="12.1xj"/>
        <vers num="12.1xl"/>
        <vers num="12.1xp"/>
        <vers num="12.1xq"/>
        <vers num="12.1xr"/>
        <vers num="12.1xs"/>
        <vers num="12.1xt"/>
        <vers num="12.1xu"/>
        <vers num="12.1xv"/>
        <vers num="12.1xw"/>
        <vers num="12.1xx"/>
        <vers num="12.1xy"/>
        <vers num="12.1xz"/>
        <vers num="12.1ya"/>
        <vers num="12.1yb"/>
        <vers num="12.1yc"/>
        <vers num="12.1yd"/>
        <vers num="12.1ye"/>
        <vers num="12.1yf"/>
        <vers num="12.1yh"/>
        <vers num="12.1yi"/>
        <vers num="12.1yj"/>
        <vers num="12.2"/>
        <vers num="12.2b"/>
        <vers num="12.2bc"/>
        <vers num="12.2bw"/>
        <vers num="12.2by"/>
        <vers num="12.2bz"/>
        <vers num="12.2cx"/>
        <vers num="12.2cy"/>
        <vers num="12.2cz"/>
        <vers num="12.2da"/>
        <vers num="12.2dd"/>
        <vers num="12.2dx"/>
        <vers num="12.2eu"/>
        <vers num="12.2ew"/>
        <vers num="12.2ewa"/>
        <vers num="12.2ex"/>
        <vers num="12.2ey"/>
        <vers num="12.2ez"/>
        <vers num="12.2fx"/>
        <vers num="12.2fy"/>
        <vers num="12.2fz"/>
        <vers num="12.2ixa"/>
        <vers num="12.2ixb"/>
        <vers num="12.2ixc"/>
        <vers num="12.2ja"/>
        <vers num="12.2jk"/>
        <vers num="12.2mb"/>
        <vers num="12.2mc"/>
        <vers num="12.2s"/>
        <vers num="12.2sb"/>
        <vers num="12.2sbc"/>
        <vers num="12.2se"/>
        <vers num="12.2sea"/>
        <vers num="12.2seb"/>
        <vers num="12.2sec"/>
        <vers num="12.2sed"/>
        <vers num="12.2see"/>
        <vers num="12.2sef"/>
        <vers num="12.2seg"/>
        <vers num="12.2sg"/>
        <vers num="12.2sga"/>
        <vers num="12.2so"/>
        <vers num="12.2sra"/>
        <vers num="12.2srb"/>
        <vers num="12.2su"/>
        <vers num="12.2sv"/>
        <vers num="12.2sw"/>
        <vers num="12.2sx"/>
        <vers num="12.2sxa"/>
        <vers num="12.2sxb"/>
        <vers num="12.2sxd"/>
        <vers num="12.2sxe"/>
        <vers num="12.2sxf"/>
        <vers num="12.2sy"/>
        <vers num="12.2sz"/>
        <vers num="12.2t"/>
        <vers num="12.2tpc"/>
        <vers num="12.2xa"/>
        <vers num="12.2xb"/>
        <vers num="12.2xc"/>
        <vers num="12.2xd"/>
        <vers num="12.2xe"/>
        <vers num="12.2xf"/>
        <vers num="12.2xg"/>
        <vers num="12.2xh"/>
        <vers num="12.2xi"/>
        <vers num="12.2xj"/>
        <vers num="12.2xk"/>
        <vers num="12.2xl"/>
        <vers num="12.2xm"/>
        <vers num="12.2xn"/>
        <vers num="12.2xq"/>
        <vers num="12.2xr"/>
        <vers num="12.2xs"/>
        <vers num="12.2xt"/>
        <vers num="12.2xu"/>
        <vers num="12.2xv"/>
        <vers num="12.2xw"/>
        <vers num="12.2ya"/>
        <vers num="12.2yb"/>
        <vers num="12.2yc"/>
        <vers num="12.2yd"/>
        <vers num="12.2ye"/>
        <vers num="12.2yf"/>
        <vers num="12.2yg"/>
        <vers num="12.2yh"/>
        <vers num="12.2yj"/>
        <vers num="12.2yk"/>
        <vers num="12.2yl"/>
        <vers num="12.2ym"/>
        <vers num="12.2yn"/>
        <vers num="12.2yo"/>
        <vers num="12.2yp"/>
        <vers num="12.2yq"/>
        <vers num="12.2yr"/>
        <vers num="12.2ys"/>
        <vers num="12.2yt"/>
        <vers num="12.2yu"/>
        <vers num="12.2yv"/>
        <vers num="12.2yw"/>
        <vers num="12.2yx"/>
        <vers num="12.2yy"/>
        <vers num="12.2yz"/>
        <vers num="12.2za"/>
        <vers num="12.2zb"/>
        <vers num="12.2zc"/>
        <vers num="12.2zd"/>
        <vers num="12.2ze"/>
        <vers num="12.2zf"/>
        <vers num="12.2zg"/>
        <vers num="12.2zh"/>
        <vers num="12.2zj"/>
        <vers num="12.2zl"/>
        <vers num="12.2zn"/>
        <vers num="12.2zp"/>
        <vers num="12.3"/>
        <vers num="12.3b"/>
        <vers num="12.3bc"/>
        <vers num="12.3bw"/>
        <vers num="12.3ja"/>
        <vers num="12.3jea"/>
        <vers num="12.3jeb"/>
        <vers num="12.3jk"/>
        <vers num="12.3jx"/>
        <vers num="12.3t"/>
        <vers num="12.3tpc"/>
        <vers num="12.3xa"/>
        <vers num="12.3xb"/>
        <vers num="12.3xc"/>
        <vers num="12.3xd"/>
        <vers num="12.3xe"/>
        <vers num="12.3xf"/>
        <vers num="12.3xg"/>
        <vers num="12.3xh"/>
        <vers num="12.3xi"/>
        <vers num="12.3xj"/>
        <vers num="12.3xk"/>
        <vers num="12.3xq"/>
        <vers num="12.3xr"/>
        <vers num="12.3xs"/>
        <vers num="12.3xu"/>
        <vers num="12.3xw"/>
        <vers num="12.3xx"/>
        <vers num="12.3xy"/>
        <vers num="12.3ya"/>
        <vers num="12.3yd"/>
        <vers num="12.3yf"/>
        <vers num="12.3yg"/>
        <vers num="12.3yh"/>
        <vers num="12.3yi"/>
        <vers num="12.3yj"/>
        <vers num="12.3yk"/>
        <vers num="12.3ym"/>
        <vers num="12.3yq"/>
        <vers num="12.3ys"/>
        <vers num="12.3yt"/>
        <vers num="12.3yu"/>
        <vers num="12.3yx"/>
        <vers num="12.3yz"/>
        <vers num="12.4"/>
        <vers num="12.4mr"/>
        <vers num="12.4sw"/>
        <vers num="12.4t"/>
        <vers num="12.4xa"/>
        <vers num="12.4xb"/>
        <vers num="12.4xc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0482" published="2007-01-24" name="CVE-2007-0482" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">cgi-bin/main in Sun Ray Server Software 2.0 and 3.0 before 20070123 allows local users to obtain the utadmin password by reading a web server's log file, or by conducting a different, unspecified local attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0316" source="VUPEN">ADV-2007-0316</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102779-1" source="SUNALERT">102779</ref>
      <ref url="http://osvdb.org/31671" source="OSVDB">31671</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31700" source="XF">sunray-utadmin-information-disclosure(31700)</ref>
      <ref url="http://www.securityfocus.com/bid/22192" source="BID">22192</ref>
      <ref url="http://securitytracker.com/id?1017547" source="SECTRACK">1017547</ref>
      <ref url="http://secunia.com/advisories/23900" source="SECUNIA">23900</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="ray_server_software">
        <vers num="2.0"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0483" published="2007-01-24" name="CVE-2007-0483" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Enthusiast 3.1 allow remote attackers to inject arbitrary web script or HTML via the URI for (1) show_owned.php or (2) show_joined.php.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23865" source="SECUNIA" adv="1">23865</ref>
      <ref url="http://osvdb.org/31608" source="OSVDB">31608</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31667" source="XF">enthusiast-show-xss(31667)</ref>
      <ref url="http://www.securityfocus.com/bid/22180" source="BID">22180</ref>
    </refs>
    <vuln_soft>
      <prod vendor="enthusiast" name="enthusiast">
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0484" published="2007-01-24" name="CVE-2007-0484" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Enthusiast 3.1 allow remote attackers to execute arbitrary SQL commands via the cat parameter to (1) show_owned.php, (2) show_joined.php, and possibly other files. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23865" source="SECUNIA" adv="1">23865</ref>
      <ref url="http://osvdb.org/31610" source="OSVDB">31610</ref>
      <ref url="http://osvdb.org/31609" source="OSVDB">31609</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31666" source="XF">enthusiast-show-sql-injection(31666)</ref>
      <ref url="http://www.securityfocus.com/bid/22180" source="BID">22180</ref>
    </refs>
    <vuln_soft>
      <prod vendor="enthusiast" name="enthusiast">
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0485" published="2007-01-24" name="CVE-2007-0485" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in defines.php in WebChat 0.77 allows remote attackers to execute arbitrary PHP code via a URL in the WEBCHATPATH parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31624" source="XF">webchat-definesphp-file-include(31624)</ref>
      <ref url="http://www.securitytracker.com/id?1006193" source="SECTRACK">1006193</ref>
      <ref url="http://www.securityfocus.com/bid/7000" source="BID">7000</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/313610/30/25700/threaded" source="BUGTRAQ">20030303 WebChat (PHP)</ref>
      <ref url="http://secunia.com/advisories/8206" source="SECUNIA">8206</ref>
      <ref url="http://milw0rm.com/exploits/3169" source="MILW0RM">3169</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webchat.org" name="webchat">
        <vers num="0.77"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0486" published="2007-01-24" name="CVE-2007-0486" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  Multiple PHP remote file inclusion vulnerabilities in Openads (aka phpAdsNew) 2.0.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) phpAds_geoPlugin parameter to libraries/lib-remotehost.inc, the (2) filename parameter to admin/report-index, or the (3) phpAds_config[my_footer] parameter to admin/lib-gui.inc.  NOTE: the vendor has disputed this issue, stating that the relevant variables are used within function definitions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22172" source="BID">22172</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457991/100/200/threaded" source="BUGTRAQ">20070124 Re: phpAdsNew 2.0.7 Remote File Include</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457806/100/200/threaded" source="BUGTRAQ">20070122 Re: phpAdsNew 2.0.7 Remote File Include</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457670/100/0/threaded" source="BUGTRAQ">20070120 phpAdsNew 2.0.7 Remote File Include</ref>
      <ref url="http://securityreason.com/securityalert/2174" source="SREASON">2174</ref>
      <ref url="http://osvdb.org/33573" source="OSVDB">33573</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpadsnew" name="phpadsnew">
        <vers num="2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0487" published="2007-01-24" name="CVE-2007-0487" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in index.php in FreeForum 0.9.0 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter. NOTE: this issue has been disputed by third party researchers, stating that fpath variable is initialized before being used.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457958/100/0/threaded" source="BUGTRAQ">20070124 Re: FreeForum 0.9.0 &lt;=- (index.php fpath) Remote File Include Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457643/100/0/threaded" source="BUGTRAQ">20070121 FreeForum 0.9.0 &lt;=- (index.php fpath) Remote File Include Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zoneo-soft" name="freeforum">
        <vers num="0.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0488" published="2007-01-24" name="CVE-2007-0488" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Huawei Versatile Routing Platform 1.43 2500E-003 firmware on the Quidway R1600 Router, and possibly other models, allows remote attackers to cause a denial of service (device crash) via a long show arp command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31641" source="XF">quidway-arp-dos(31641)</ref>
      <ref url="http://osvdb.org/40355" source="OSVDB">40355</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051856.html" source="FULLDISC">20070118 The Quidway Router local DOS</ref>
      <ref url="http://securityreason.com/securityalert/2176" source="SREASON">2176</ref>
    </refs>
    <vuln_soft>
      <prod vendor="huawei" name="versatile_routing_platform">
        <vers num="1.43_2500e-003_firmware"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0489" published="2007-01-24" name="CVE-2007-0489" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in includes/functions.visohotlink.php in VisoHotlink 1.01 and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31654" source="XF">visohotlink-functions-file-include(31654)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0285" source="VUPEN">ADV-2007-0285</ref>
      <ref url="http://secunia.com/advisories/23878" source="SECUNIA" adv="1">23878</ref>
      <ref url="http://osvdb.org/31611" source="OSVDB">31611</ref>
      <ref url="http://milw0rm.com/exploits/3175" source="MILW0RM">3175</ref>
      <ref url="http://www.securityfocus.com/bid/22171" source="BID">22171</ref>
    </refs>
    <vuln_soft>
      <prod vendor="visohotlink" name="visohotlink">
        <vers prev="1" num="1.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0490" published="2007-01-24" name="CVE-2007-0490" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">index.php in Open-Realty 2.3.4 allows remote attackers to obtain sensitive information (the full path) via an invalid listingID parameter in a listingview action.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457676/100/0/threaded" source="BUGTRAQ">20070121 Full Path Disclosure in Open-Realty ( v2.3.4 )</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31657" source="XF">openrealty-index-path-disclosure(31657)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="open-realty" name="open-realty">
        <vers num="2.3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0491" published="2007-01-24" name="CVE-2007-0491" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in up.php in Sky GUNNING MySpeach 3.0.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the my_ms[root] parameter, a different vector than CVE-2006-4630.  NOTE: Some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0269" source="VUPEN">ADV-2007-0269</ref>
      <ref url="http://secunia.com/advisories/23850" source="SECUNIA" adv="1">23850</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sky_gunning" name="myspeach">
        <vers prev="1" num="3.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0492" published="2007-01-24" name="CVE-2007-0492" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in gallery.php in webSPELL 4.01.02 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) galleryID parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0270" source="VUPEN">ADV-2007-0270</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31632" source="XF">webspell-gallery-sql-injection(31632)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webspell" name="webspell">
        <vers prev="1" num="4.01.02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0493" published="2007-01-25" name="CVE-2007-0493" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (named daemon crash) via unspecified vectors that cause named to "dereference a freed fetch context."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.isc.org/index.pl?/sw/bind/view/?release=9.3.4" source="CONFIRM" patch="1">http://www.isc.org/index.pl?/sw/bind/view/?release=9.3.4</ref>
      <ref url="http://www.isc.org/index.pl?/sw/bind/view/?release=9.2.8" source="CONFIRM" patch="1">http://www.isc.org/index.pl?/sw/bind/view/?release=9.2.8</ref>
      <ref url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144" source="HP">SSRT061239</ref>
      <ref url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144" source="HP">SSRT071304</ref>
      <ref url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144" source="HP">SSRT061213</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2315" source="VUPEN">ADV-2007-2315</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2163" source="VUPEN">ADV-2007-2163</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1939" source="VUPEN">ADV-2007-1939</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1401" source="VUPEN">ADV-2007-1401</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0349" source="VUPEN">ADV-2007-0349</ref>
      <ref url="http://secunia.com/advisories/23904" source="SECUNIA" adv="1">23904</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9614" source="OVAL">oval:org.mitre.oval:def:9614</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bind-announce&amp;m=116968519321296&amp;w=2" source="MLIST">[bind-announce] 20070125 Internet Systems Consortium Security Advisory.</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/052018.html" source="FULLDISC">20070125 BIND remote exploit (low severity) [Fwd: Internet Systems Consortium Security Advisory.]</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01070495" source="HP">SSRT061273</ref>
      <ref url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144" source="HP">SSRT061213</ref>
      <ref url="https://issues.rpath.com/browse/RPL-989" source="CONFIRM">https://issues.rpath.com/browse/RPL-989</ref>
      <ref url="http://www.ubuntu.com/usn/usn-418-1" source="UBUNTU">USN-418-1</ref>
      <ref url="http://www.trustix.org/errata/2007/0005" source="TRUSTIX">2007-0005</ref>
      <ref url="http://www.securityfocus.com/bid/22229" source="BID">22229</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458066/100/0/threaded" source="BUGTRAQ">20070125 BIND remote exploit (low severity) [Fwd: Internet Systems Consortium Security Advisory.]</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0057.html" source="REDHAT">RHSA-2007:0057</ref>
      <ref url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.007.html" source="OPENPKG">OpenPKG-SA-2007.007</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:030" source="MANDRIVA">MDKSA-2007:030</ref>
      <ref url="http://www.isc.org/index.pl?/sw/bind/bind-security.php" source="CONFIRM">http://www.isc.org/index.pl?/sw/bind/bind-security.php</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.494157" source="SLACKWARE">SSA:2007-026-01</ref>
      <ref url="http://securitytracker.com/id?1017561" source="SECTRACK">1017561</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200702-06.xml" source="GENTOO">GLSA-200702-06</ref>
      <ref url="http://security.freebsd.org/advisories/FreeBSD-SA-07:02.bind.asc" source="FREEBSD">FreeBSD-SA-07:02</ref>
      <ref url="http://secunia.com/advisories/25649" source="SECUNIA">25649</ref>
      <ref url="http://secunia.com/advisories/25402" source="SECUNIA">25402</ref>
      <ref url="http://secunia.com/advisories/24950" source="SECUNIA">24950</ref>
      <ref url="http://secunia.com/advisories/24930" source="SECUNIA">24930</ref>
      <ref url="http://secunia.com/advisories/24203" source="SECUNIA">24203</ref>
      <ref url="http://secunia.com/advisories/24129" source="SECUNIA">24129</ref>
      <ref url="http://secunia.com/advisories/24054" source="SECUNIA">24054</ref>
      <ref url="http://secunia.com/advisories/24048" source="SECUNIA">24048</ref>
      <ref url="http://secunia.com/advisories/24014" source="SECUNIA">24014</ref>
      <ref url="http://secunia.com/advisories/23977" source="SECUNIA">23977</ref>
      <ref url="http://secunia.com/advisories/23974" source="SECUNIA">23974</ref>
      <ref url="http://secunia.com/advisories/23972" source="SECUNIA">23972</ref>
      <ref url="http://secunia.com/advisories/23943" source="SECUNIA">23943</ref>
      <ref url="http://secunia.com/advisories/23924" source="SECUNIA">23924</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0016.html" source="SUSE">SUSE-SA:2007:014</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html" source="APPLE">APPLE-SA-2007-05-24</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01070495" source="HP">HPSBUX02219</ref>
      <ref url="http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2007-003.txt.asc" source="NETBSD">NetBSD-SA2007-003</ref>
      <ref url="http://fedoranews.org/cms/node/2537" source="FEDORA">FEDORA-2007-164</ref>
      <ref url="http://fedoranews.org/cms/node/2507" source="FEDORA">FEDORA-2007-147</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305530" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305530</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="9.3.0"/>
        <vers num="9.3.1"/>
        <vers num="9.3.2"/>
        <vers num="9.4.0" edition="rc1"/>
        <vers num="9.4.0a1"/>
        <vers num="9.4.0a2"/>
        <vers num="9.4.0a3"/>
        <vers num="9.4.0a4"/>
        <vers num="9.4.0a5"/>
        <vers num="9.4.0b1"/>
        <vers num="9.4.0b2"/>
        <vers num="9.4.0b3"/>
        <vers num="9.5.0a1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0494" published="2007-01-25" name="CVE-2007-0494" modified="2011-10-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the "DNSSEC Validation" vulnerability.</descript>
    </desc>
    <sols>
      <sol source="nvd">Syccessful exploitation requires that the victim has enabled dnssec validation in named.conf by specifying trusted-keys.</sol>
    </sols>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.isc.org/index.pl?/sw/bind/view/?release=9.3.4" source="CONFIRM" patch="1">http://www.isc.org/index.pl?/sw/bind/view/?release=9.3.4</ref>
      <ref url="http://www.isc.org/index.pl?/sw/bind/view/?release=9.2.8" source="CONFIRM" patch="1">http://www.isc.org/index.pl?/sw/bind/view/?release=9.2.8</ref>
      <ref url="http://secunia.com/advisories/23904" source="SECUNIA" patch="1" adv="1">23904</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bind-announce&amp;m=116968519300764&amp;w=2" source="MLIST" patch="1">[bind-announce] 20070125 Internet Systems Consortium Security Advisory.</ref>
      <ref url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144" source="HP">SSRT071304</ref>
      <ref url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144" source="HP">SSRT061239</ref>
      <ref url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144" source="HP">SSRT071304</ref>
      <ref url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144" source="HP">SSRT061213</ref>
      <ref url="https://issues.rpath.com/browse/RPL-989" source="CONFIRM">https://issues.rpath.com/browse/RPL-989</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3229" source="VUPEN">ADV-2007-3229</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2315" source="VUPEN">ADV-2007-2315</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2245" source="VUPEN">ADV-2007-2245</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2163" source="VUPEN">ADV-2007-2163</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2002" source="VUPEN">ADV-2007-2002</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1939" source="VUPEN">ADV-2007-1939</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1401" source="VUPEN">ADV-2007-1401</ref>
      <ref url="http://www.ubuntu.com/usn/usn-418-1" source="UBUNTU">USN-418-1</ref>
      <ref url="http://www.trustix.org/errata/2007/0005" source="TRUSTIX">2007-0005</ref>
      <ref url="http://www.securityfocus.com/bid/22231" source="BID">22231</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0057.html" source="REDHAT">RHSA-2007:0057</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0044.html" source="REDHAT">RHSA-2007:0044</ref>
      <ref url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.007.html" source="OPENPKG">OpenPKG-SA-2007.007</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:030" source="MANDRIVA">MDKSA-2007:030</ref>
      <ref url="http://www.isc.org/index.pl?/sw/bind/bind-security.php" source="CONFIRM">http://www.isc.org/index.pl?/sw/bind/bind-security.php</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1254" source="DEBIAN">DSA-1254</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY96324" source="AIXAPAR">IY96324</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY96144" source="AIXAPAR">IY96144</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY95619" source="AIXAPAR">IY95619</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY95618" source="AIXAPAR">IY95618</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-125.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-125.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102969-1" source="SUNALERT">102969</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.494157" source="SLACKWARE">SSA:2007-026-01</ref>
      <ref url="http://securitytracker.com/id?1017573" source="SECTRACK">1017573</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200702-06.xml" source="GENTOO">GLSA-200702-06</ref>
      <ref url="http://security.freebsd.org/advisories/FreeBSD-SA-07:02.bind.asc" source="FREEBSD">FreeBSD-SA-07:02</ref>
      <ref url="http://secunia.com/advisories/25402" source="SECUNIA" adv="1">25402</ref>
      <ref url="http://secunia.com/advisories/24950" source="SECUNIA" adv="1">24950</ref>
      <ref url="http://secunia.com/advisories/24930" source="SECUNIA" adv="1">24930</ref>
      <ref url="http://secunia.com/advisories/24648" source="SECUNIA" adv="1">24648</ref>
      <ref url="http://secunia.com/advisories/24203" source="SECUNIA" adv="1">24203</ref>
      <ref url="http://secunia.com/advisories/24129" source="SECUNIA" adv="1">24129</ref>
      <ref url="http://secunia.com/advisories/24083" source="SECUNIA" adv="1">24083</ref>
      <ref url="http://secunia.com/advisories/24054" source="SECUNIA" adv="1">24054</ref>
      <ref url="http://secunia.com/advisories/24048" source="SECUNIA" adv="1">24048</ref>
      <ref url="http://secunia.com/advisories/24014" source="SECUNIA" adv="1">24014</ref>
      <ref url="http://secunia.com/advisories/23977" source="SECUNIA" adv="1">23977</ref>
      <ref url="http://secunia.com/advisories/23974" source="SECUNIA" adv="1">23974</ref>
      <ref url="http://secunia.com/advisories/23972" source="SECUNIA" adv="1">23972</ref>
      <ref url="http://secunia.com/advisories/23944" source="SECUNIA" adv="1">23944</ref>
      <ref url="http://secunia.com/advisories/23943" source="SECUNIA" adv="1">23943</ref>
      <ref url="http://secunia.com/advisories/23924" source="SECUNIA" adv="1">23924</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11523" source="OVAL">oval:org.mitre.oval:def:11523</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0016.html" source="SUSE">SUSE-SA:2007:014</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html" source="FULLDISC">20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html" source="APPLE">APPLE-SA-2007-05-24</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01070495" source="HP">SSRT061273</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01070495" source="HP">SSRT061273</ref>
      <ref url="http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2007-003.txt.asc" source="NETBSD">NetBSD-SA2007-003</ref>
      <ref url="http://fedoranews.org/cms/node/2537" source="FEDORA">FEDORA-2007-164</ref>
      <ref url="http://fedoranews.org/cms/node/2507" source="FEDORA">FEDORA-2007-147</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305530" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305530</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc" source="SGI">20070201-01-P</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31838" source="XF">bind-rrsets-dos(31838)</ref>
      <ref url="http://secunia.com/advisories/27706" source="SECUNIA">27706</ref>
      <ref url="http://secunia.com/advisories/26909" source="SECUNIA">26909</ref>
      <ref url="http://secunia.com/advisories/25715" source="SECUNIA">25715</ref>
      <ref url="http://secunia.com/advisories/25649" source="SECUNIA">25649</ref>
      <ref url="http://secunia.com/advisories/25482" source="SECUNIA">25482</ref>
      <ref url="http://secunia.com/advisories/24284" source="SECUNIA">24284</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="9.0"/>
        <vers num="9.0.1"/>
        <vers num="9.1"/>
        <vers num="9.1.1"/>
        <vers num="9.1.2"/>
        <vers num="9.1.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
        <vers num="9.2.2"/>
        <vers num="9.2.3"/>
        <vers num="9.2.4"/>
        <vers num="9.2.5"/>
        <vers num="9.2.6"/>
        <vers num="9.2.7"/>
        <vers num="9.3"/>
        <vers num="9.3.1"/>
        <vers num="9.3.2"/>
        <vers num="9.3.3"/>
        <vers num="9.4.0" edition="rc1"/>
        <vers num="9.4.0a1"/>
        <vers num="9.4.0a2"/>
        <vers num="9.4.0a3"/>
        <vers num="9.4.0a4"/>
        <vers num="9.4.0a5"/>
        <vers num="9.4.0a6"/>
        <vers num="9.4.0b1"/>
        <vers num="9.4.0b2"/>
        <vers num="9.4.0b3"/>
        <vers num="9.4.0b4"/>
        <vers num="9.5.0a1" edition=""/>
        <vers num="9.5.0a1" edition=":bind_forum"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0495" published="2007-01-25" name="CVE-2007-0495" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in include/config.inc.php in PhpSherpa allows remote attackers to execute arbitrary PHP code via a URL in the racine parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0263" source="VUPEN">ADV-2007-0263</ref>
      <ref url="http://secunia.com/advisories/23817" source="SECUNIA" adv="1">23817</ref>
      <ref url="http://osvdb.org/31599" source="OSVDB">31599</ref>
      <ref url="http://milw0rm.com/exploits/3161" source="MILW0RM">3161</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpsherpa" name="phpsherpa">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0496" published="2007-01-25" name="CVE-2007-0496" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in lib/nl/nl.php in Neon Labs Website (nlws) 3.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the g_strRootDir parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0268" source="VUPEN">ADV-2007-0268</ref>
      <ref url="http://osvdb.org/36797" source="OSVDB">36797</ref>
      <ref url="http://milw0rm.com/exploits/3163" source="MILW0RM">3163</ref>
    </refs>
    <vuln_soft>
      <prod vendor="neon_labs" name="neon_labs_website">
        <vers prev="1" num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0497" published="2007-01-25" name="CVE-2007-0497" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in upload/top.php in Upload-Service 1.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the maindir parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0265" source="VUPEN">ADV-2007-0265</ref>
      <ref url="http://secunia.com/advisories/23845" source="SECUNIA" adv="1">23845</ref>
      <ref url="http://osvdb.org/32938" source="OSVDB">32938</ref>
      <ref url="http://echo.or.id/adv/adv62-y3dips-2007.txt" source="MISC">http://echo.or.id/adv/adv62-y3dips-2007.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31634" source="XF">uploadservice-top-file-include(31634)</ref>
      <ref url="http://www.securityfocus.com/bid/22189" source="BID">22189</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457800/100/100/threaded" source="BUGTRAQ">20070123 [ECHO_ADV_62$2007] Upload Service 1.0 remote file inclusion</ref>
    </refs>
    <vuln_soft>
      <prod vendor="upload-service" name="upload-service">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0498" published="2007-01-25" name="CVE-2007-0498" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in up.php in MySpeach 2.1 beta and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the my[root] parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://osvdb.org/31603" source="OSVDB">31603</ref>
      <ref url="http://milw0rm.com/exploits/3165" source="MILW0RM">3165</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sky_gunning" name="myspeach">
        <vers num="2.1_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0499" published="2007-01-25" name="CVE-2007-0499" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in config.php in Sangwan Kim phpIndexPage 1.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the env[inc_path] parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0267" source="VUPEN">ADV-2007-0267</ref>
      <ref url="http://www.securityfocus.com/bid/22161" source="BID">22161</ref>
      <ref url="http://secunia.com/advisories/23992" source="SECUNIA" adv="1">23992</ref>
      <ref url="http://osvdb.org/33014" source="OSVDB">33014</ref>
      <ref url="http://milw0rm.com/exploits/3164" source="MILW0RM">3164</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sangwan_kim" name="phpindexpage">
        <vers prev="1" num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0500" published="2007-01-25" name="CVE-2007-0500" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in include/includes.php in Bradabra 2.0.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0264" source="VUPEN">ADV-2007-0264</ref>
      <ref url="http://secunia.com/advisories/23851" source="SECUNIA" adv="1">23851</ref>
      <ref url="http://osvdb.org/31604" source="OSVDB">31604</ref>
      <ref url="http://milw0rm.com/exploits/3162" source="MILW0RM">3162</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bradabra" name="bradabra">
        <vers prev="1" num="2.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0501" published="2007-01-25" name="CVE-2007-0501" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in Mafia Scum Tools 2.0.0 in Matthew Wardrop Advanced Random Generators (adv-random-gen) allows remote attackers to execute arbitrary PHP code via a URL in the gen parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31637" source="XF">mafiascum-index-file-include(31637)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0271" source="VUPEN">ADV-2007-0271</ref>
      <ref url="http://www.securityfocus.com/bid/22151" source="BID">22151</ref>
      <ref url="http://osvdb.org/36810" source="OSVDB">36810</ref>
      <ref url="http://milw0rm.com/exploits/3171" source="MILW0RM">3171</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mafia_scum_tools" name="mafia_scum_tools">
        <vers prev="1" num="2.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0502" published="2007-01-25" name="CVE-2007-0502" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote attackers to execute arbitrary SQL commands via the picID parameter, a different vector than CVE-2007-0492.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0270" source="VUPEN">ADV-2007-0270</ref>
      <ref url="http://osvdb.org/36798" source="OSVDB">36798</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31632" source="XF">webspell-gallery-sql-injection(31632)</ref>
      <ref url="http://www.securityfocus.com/bid/22149" source="BID">22149</ref>
      <ref url="http://milw0rm.com/exploits/3172" source="MILW0RM">3172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webspell" name="webspell">
        <vers num="4.01.02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0503" published="2007-01-25" name="CVE-2007-0503" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in kcms_calibrate in Sun Solaris 8 and 9 before 20071122 allows local users to execute arbitrary commands via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102728-1" source="SUNALERT" patch="1" adv="1">102728</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31668" source="XF">solaris-kcmscalibrate-privilege-escalation(31668)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0287" source="VUPEN">ADV-2007-0287</ref>
      <ref url="http://securitytracker.com/id?1017541" source="SECTRACK">1017541</ref>
      <ref url="http://secunia.com/advisories/23885" source="SECUNIA">23885</ref>
      <ref url="http://osvdb.org/31598" source="OSVDB">31598</ref>
      <ref url="http://www.securityfocus.com/bid/22175" source="BID">22175</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-040.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-040.htm</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1495" source="OVAL" sig="1">oval:org.mitre.oval:def:1495</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0504" published="2007-01-25" name="CVE-2007-0504" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Eval injection vulnerability in poll_frame.php in Vote! Pro 4.0, and possibly other scripts, allows remote attackers to execute arbitrary code via the poll_id parameter, which is supplied to an eval function call, a different vulnerability type than CVE-2005-4632.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1" other="1" admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/eng