<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://nvd.nist.gov/feeds/cve/1.2" nvd_xml_version="1.2" pub_date="2013-05-22" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd">
  <entry type="CVE" severity="Low" seq="2008-0001" published="2008-01-15" name="CVE-2008-0001" modified="2012-03-19" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">VFS in the Linux kernel before 2.6.22.16, and 2.6.23.x before 2.6.23.14, performs tests of access mode by using the flag variable instead of the acc_mode variable, which might allow local users to bypass intended permissions and remove directories.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27280" source="BID" patch="1">27280</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00828.html" source="FEDORA">FEDORA-2008-0748</ref>
      <ref url="https://issues.rpath.com/browse/RPL-2146" source="CONFIRM">https://issues.rpath.com/browse/RPL-2146</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39672" source="XF">linux-directory-security-bypass(39672)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0151" source="VUPEN" adv="1">ADV-2008-0151</ref>
      <ref url="http://www.ubuntu.com/usn/usn-578-1" source="UBUNTU">USN-578-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-574-1" source="UBUNTU">USN-574-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486485/100/0/threaded" source="BUGTRAQ">20080117 rPSA-2008-0021-1 kernel</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0089.html" source="REDHAT">RHSA-2008:0089</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:112" source="MANDRIVA">MDVSA-2008:112</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:044" source="MANDRIVA">MDVSA-2008:044</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.23.14" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.23.14</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1479" source="DEBIAN">DSA-1479</ref>
      <ref url="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0021" source="CONFIRM">http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0021</ref>
      <ref url="http://securitytracker.com/id?1019289" source="SECTRACK">1019289</ref>
      <ref url="http://secunia.com/advisories/29245" source="SECUNIA" adv="1">29245</ref>
      <ref url="http://secunia.com/advisories/28971" source="SECUNIA" adv="1">28971</ref>
      <ref url="http://secunia.com/advisories/28806" source="SECUNIA" adv="1">28806</ref>
      <ref url="http://secunia.com/advisories/28748" source="SECUNIA" adv="1">28748</ref>
      <ref url="http://secunia.com/advisories/28706" source="SECUNIA" adv="1">28706</ref>
      <ref url="http://secunia.com/advisories/28664" source="SECUNIA" adv="1">28664</ref>
      <ref url="http://secunia.com/advisories/28643" source="SECUNIA" adv="1">28643</ref>
      <ref url="http://secunia.com/advisories/28628" source="SECUNIA" adv="1">28628</ref>
      <ref url="http://secunia.com/advisories/28626" source="SECUNIA" adv="1">28626</ref>
      <ref url="http://secunia.com/advisories/28558" source="SECUNIA" adv="1">28558</ref>
      <ref url="http://secunia.com/advisories/28485" source="SECUNIA" adv="1">28485</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2008-0055.html" source="REDHAT">RHSA-2008:0055</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9709" source="OVAL">oval:org.mitre.oval:def:9709</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00002.html" source="SUSE">SUSE-SA:2008:013</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00002.html" source="SUSE">SUSE-SA:2008:006</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.16" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.16</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=974a9f0b47da74e28f68b9c8645c3786aa5ace1a" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=974a9f0b47da74e28f68b9c8645c3786aa5ace1a</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.10"/>
        <vers num="2.6.11"/>
        <vers num="2.6.11.1"/>
        <vers num="2.6.11.10"/>
        <vers num="2.6.11.11"/>
        <vers num="2.6.11.12"/>
        <vers num="2.6.11.2"/>
        <vers num="2.6.11.3"/>
        <vers num="2.6.11.4"/>
        <vers num="2.6.11.5"/>
        <vers num="2.6.11.6"/>
        <vers num="2.6.11.7"/>
        <vers num="2.6.11.8"/>
        <vers num="2.6.11.9"/>
        <vers num="2.6.12"/>
        <vers num="2.6.12.1"/>
        <vers num="2.6.12.2"/>
        <vers num="2.6.12.3"/>
        <vers num="2.6.12.4"/>
        <vers num="2.6.12.5"/>
        <vers num="2.6.12.6"/>
        <vers num="2.6.13"/>
        <vers num="2.6.13.1"/>
        <vers num="2.6.13.2"/>
        <vers num="2.6.13.3"/>
        <vers num="2.6.13.4"/>
        <vers num="2.6.13.5"/>
        <vers num="2.6.14"/>
        <vers num="2.6.14.1"/>
        <vers num="2.6.14.2"/>
        <vers num="2.6.14.3"/>
        <vers num="2.6.14.4"/>
        <vers num="2.6.14.5"/>
        <vers num="2.6.14.6"/>
        <vers num="2.6.14.7"/>
        <vers num="2.6.15"/>
        <vers num="2.6.15.1"/>
        <vers num="2.6.15.2"/>
        <vers num="2.6.15.3"/>
        <vers num="2.6.15.4"/>
        <vers num="2.6.15.5"/>
        <vers num="2.6.15.6"/>
        <vers num="2.6.15.7"/>
        <vers num="2.6.16" edition="rc1"/>
        <vers num="2.6.16.1"/>
        <vers num="2.6.16.10"/>
        <vers num="2.6.16.11"/>
        <vers num="2.6.16.12"/>
        <vers num="2.6.16.13"/>
        <vers num="2.6.16.14"/>
        <vers num="2.6.16.15"/>
        <vers num="2.6.16.16"/>
        <vers num="2.6.16.17"/>
        <vers num="2.6.16.18"/>
        <vers num="2.6.16.19"/>
        <vers num="2.6.16.2"/>
        <vers num="2.6.16.20"/>
        <vers num="2.6.16.21"/>
        <vers num="2.6.16.22"/>
        <vers num="2.6.16.23"/>
        <vers num="2.6.16.24"/>
        <vers num="2.6.16.25"/>
        <vers num="2.6.16.26"/>
        <vers num="2.6.16.27"/>
        <vers num="2.6.16.28"/>
        <vers num="2.6.16.29"/>
        <vers num="2.6.16.3"/>
        <vers num="2.6.16.30"/>
        <vers num="2.6.16.31" edition="-rc1"/>
        <vers num="2.6.16.31" edition="-rc2"/>
        <vers num="2.6.16.31" edition="-rc3"/>
        <vers num="2.6.16.31" edition="-rc4"/>
        <vers num="2.6.16.31" edition="-rc5"/>
        <vers num="2.6.16.32"/>
        <vers num="2.6.16.33"/>
        <vers num="2.6.16.34"/>
        <vers num="2.6.16.35"/>
        <vers num="2.6.16.36"/>
        <vers num="2.6.16.37"/>
        <vers num="2.6.16.38"/>
        <vers num="2.6.16.39"/>
        <vers num="2.6.16.4"/>
        <vers num="2.6.16.40"/>
        <vers num="2.6.16.41"/>
        <vers num="2.6.16.42"/>
        <vers num="2.6.16.43"/>
        <vers num="2.6.16.44"/>
        <vers num="2.6.16.45"/>
        <vers num="2.6.16.46"/>
        <vers num="2.6.16.47"/>
        <vers num="2.6.16.48"/>
        <vers num="2.6.16.49"/>
        <vers num="2.6.16.5"/>
        <vers num="2.6.16.50"/>
        <vers num="2.6.16.51"/>
        <vers num="2.6.16.52"/>
        <vers num="2.6.16.53"/>
        <vers num="2.6.16.54"/>
        <vers num="2.6.16.55"/>
        <vers num="2.6.16.56"/>
        <vers num="2.6.16.57"/>
        <vers num="2.6.16.58"/>
        <vers num="2.6.16.59"/>
        <vers num="2.6.16.6"/>
        <vers num="2.6.16.60"/>
        <vers num="2.6.16.61"/>
        <vers num="2.6.16.62"/>
        <vers num="2.6.16.7"/>
        <vers num="2.6.16.8"/>
        <vers num="2.6.16.9"/>
        <vers num="2.6.17" edition="rc1"/>
        <vers num="2.6.17" edition="rc2"/>
        <vers num="2.6.17" edition="rc3"/>
        <vers num="2.6.17" edition="rc4"/>
        <vers num="2.6.17" edition="rc5"/>
        <vers num="2.6.17" edition="rc6"/>
        <vers num="2.6.17.1"/>
        <vers num="2.6.17.10"/>
        <vers num="2.6.17.11"/>
        <vers num="2.6.17.12"/>
        <vers num="2.6.17.13"/>
        <vers num="2.6.17.14"/>
        <vers num="2.6.17.2"/>
        <vers num="2.6.17.3"/>
        <vers num="2.6.17.4"/>
        <vers num="2.6.17.5"/>
        <vers num="2.6.17.6"/>
        <vers num="2.6.17.7"/>
        <vers num="2.6.17.8"/>
        <vers num="2.6.17.9"/>
        <vers num="2.6.18" edition="rc1"/>
        <vers num="2.6.18" edition="rc2"/>
        <vers num="2.6.18" edition="rc3"/>
        <vers num="2.6.18" edition="rc4"/>
        <vers num="2.6.18" edition="rc5"/>
        <vers num="2.6.18" edition="rc6"/>
        <vers num="2.6.18" edition="rc7"/>
        <vers num="2.6.18.1"/>
        <vers num="2.6.18.2"/>
        <vers num="2.6.18.3"/>
        <vers num="2.6.18.4"/>
        <vers num="2.6.18.5"/>
        <vers num="2.6.18.6"/>
        <vers num="2.6.18.7"/>
        <vers num="2.6.18.8"/>
        <vers num="2.6.19"/>
        <vers num="2.6.19.1"/>
        <vers num="2.6.19.2"/>
        <vers num="2.6.19.3"/>
        <vers num="2.6.19.4"/>
        <vers num="2.6.19.5"/>
        <vers num="2.6.19.6"/>
        <vers num="2.6.19.7"/>
        <vers num="2.6.2"/>
        <vers num="2.6.20"/>
        <vers num="2.6.20.1"/>
        <vers num="2.6.20.10"/>
        <vers num="2.6.20.11"/>
        <vers num="2.6.20.12"/>
        <vers num="2.6.20.13"/>
        <vers num="2.6.20.14"/>
        <vers num="2.6.20.15"/>
        <vers num="2.6.20.16"/>
        <vers num="2.6.20.17"/>
        <vers num="2.6.20.18"/>
        <vers num="2.6.20.19"/>
        <vers num="2.6.20.2"/>
        <vers num="2.6.20.20"/>
        <vers num="2.6.20.21"/>
        <vers num="2.6.20.3"/>
        <vers num="2.6.20.4"/>
        <vers num="2.6.20.5"/>
        <vers num="2.6.20.6"/>
        <vers num="2.6.20.7"/>
        <vers num="2.6.20.8"/>
        <vers num="2.6.20.9"/>
        <vers num="2.6.21"/>
        <vers num="2.6.21.1"/>
        <vers num="2.6.21.2"/>
        <vers num="2.6.21.3"/>
        <vers num="2.6.21.4"/>
        <vers num="2.6.21.5"/>
        <vers num="2.6.21.6"/>
        <vers num="2.6.21.7"/>
        <vers num="2.6.22"/>
        <vers num="2.6.22.1"/>
        <vers num="2.6.22.10"/>
        <vers num="2.6.22.11"/>
        <vers num="2.6.22.12"/>
        <vers num="2.6.22.13"/>
        <vers num="2.6.22.14"/>
        <vers prev="1" num="2.6.22.15"/>
        <vers num="2.6.22.2"/>
        <vers num="2.6.22.3"/>
        <vers num="2.6.22.4"/>
        <vers num="2.6.22.5"/>
        <vers num="2.6.22.6"/>
        <vers num="2.6.22.7"/>
        <vers num="2.6.22.8"/>
        <vers num="2.6.22.9"/>
        <vers num="2.6.23" edition="rc1"/>
        <vers num="2.6.23" edition="rc2"/>
        <vers num="2.6.23.1"/>
        <vers num="2.6.23.10"/>
        <vers num="2.6.23.11"/>
        <vers num="2.6.23.12"/>
        <vers num="2.6.23.13"/>
        <vers num="2.6.23.2"/>
        <vers num="2.6.23.3"/>
        <vers num="2.6.23.4"/>
        <vers num="2.6.23.5"/>
        <vers num="2.6.23.6"/>
        <vers num="2.6.23.7"/>
        <vers num="2.6.23.8"/>
        <vers num="2.6.23.9"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6"/>
        <vers num="2.6.7"/>
        <vers num="2.6.8"/>
        <vers num="2.6.8.1"/>
        <vers num="2.6.9" edition="rc1"/>
        <vers num="2.6.9" edition="rc2"/>
        <vers num="2.6.9" edition="rc3"/>
        <vers num="2.6.9" edition="rc4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0002" published="2008-02-11" name="CVE-2008-0002" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attackers to obtain sensitive information, as demonstrated by disconnecting during this processing in order to trigger the exception.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00460.html" source="FEDORA">FEDORA-2008-1603</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00315.html" source="FEDORA">FEDORA-2008-1467</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/2780" source="VUPEN">ADV-2008-2780</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0488" source="VUPEN">ADV-2008-0488</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.securityfocus.com/bid/31681" source="BID">31681</ref>
      <ref url="http://www.securityfocus.com/bid/27703" source="BID">27703</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487812/100/0/threaded" source="BUGTRAQ">20080208 CVE-2008-0002: Tomcat information disclosure vulnerability</ref>
      <ref url="http://tomcat.apache.org/security-6.html" source="CONFIRM">http://tomcat.apache.org/security-6.html</ref>
      <ref url="http://support.apple.com/kb/HT3216" source="CONFIRM">http://support.apple.com/kb/HT3216</ref>
      <ref url="http://securityreason.com/securityalert/3638" source="SREASON">3638</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200804-10.xml" source="GENTOO">GLSA-200804-10</ref>
      <ref url="http://secunia.com/advisories/37460" source="SECUNIA">37460</ref>
      <ref url="http://secunia.com/advisories/32222" source="SECUNIA">32222</ref>
      <ref url="http://secunia.com/advisories/29711" source="SECUNIA">29711</ref>
      <ref url="http://secunia.com/advisories/28915" source="SECUNIA">28915</ref>
      <ref url="http://secunia.com/advisories/28834" source="SECUNIA">28834</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html" source="SUSE">SUSE-SR:2009:004</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html" source="APPLE">APPLE-SA-2008-10-09</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers num="6.0.10"/>
        <vers num="6.0.11"/>
        <vers num="6.0.12"/>
        <vers num="6.0.13"/>
        <vers num="6.0.14"/>
        <vers num="6.0.15"/>
        <vers num="6.0.5"/>
        <vers num="6.0.6"/>
        <vers num="6.0.7"/>
        <vers num="6.0.8"/>
        <vers num="6.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0003" published="2008-01-08" name="CVE-2008-0003" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the PAMBasicAuthenticator::PAMCallback function in OpenPegasus CIM management server (tog-pegasus), when compiled to use PAM and without PEGASUS_USE_PAM_STANDALONE_PROC defined, might allow remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2007-5360.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27188" source="BID" patch="1">27188</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0002.html" source="REDHAT" patch="1">RHSA-2008:0002</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00480.html" source="FEDORA">FEDORA-2008-0572</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00424.html" source="FEDORA">FEDORA-2008-0506</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=426578" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=426578</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39527" source="XF">openpegasus-pambasic-bo(39527)</ref>
      <ref url="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=4129" source="CONFIRM">http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=4129</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1391/references" source="VUPEN" adv="1">ADV-2008-1391</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1234/references" source="VUPEN" adv="1">ADV-2008-1234</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0638" source="VUPEN" adv="1">ADV-2008-0638</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0063" source="VUPEN" adv="1">ADV-2008-0063</ref>
      <ref url="http://www.securityfocus.com/bid/27172" source="BID">27172</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/490917/100/0/threaded" source="BUGTRAQ">20080416 VMSA-2008-0007 Moderate Updated Service Console packages pcre, net-snmp, and OpenPegasus</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2008-January/001879.html" source="VIM">20080115 vuldb confusion between OpenPegasus issues</ref>
      <ref url="http://securitytracker.com/id?1019159" source="SECTRACK">1019159</ref>
      <ref url="http://secunia.com/advisories/29986" source="SECUNIA" adv="1">29986</ref>
      <ref url="http://secunia.com/advisories/29785" source="SECUNIA" adv="1">29785</ref>
      <ref url="http://secunia.com/advisories/29056" source="SECUNIA" adv="1">29056</ref>
      <ref url="http://secunia.com/advisories/28462" source="SECUNIA" adv="1">28462</ref>
      <ref url="http://secunia.com/advisories/28338" source="SECUNIA" adv="1">28338</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10282" source="OVAL">oval:org.mitre.oval:def:10282</ref>
      <ref url="http://osvdb.org/40082" source="OSVDB">40082</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2008/000014.html" source="MLIST">[Security-announce] 20080415 VMSA-2008-0007 Moderate Updated Service Console packages pcre, net-snmp, and OpenPegasus</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01438409" source="HP">SSRT080000</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01438409" source="HP">HPSBMA02331</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openpegasus" name="management_server">
        <vers num="2.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2008-0004" reject="1" published="2009-03-26" name="CVE-2008-0004" modified="2009-03-26">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0005" published="2008-01-11" name="CVE-2008-0005" modified="2011-09-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00562.html" source="FEDORA">FEDORA-2008-1695</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00541.html" source="FEDORA">FEDORA-2008-1711</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39615" source="XF">apache-modproxyftp-utf7-xss(39615)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1875/references" source="VUPEN">ADV-2008-1875</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN">ADV-2008-0924</ref>
      <ref url="http://www.ubuntu.com/usn/usn-575-1" source="UBUNTU">USN-575-1</ref>
      <ref url="http://www.securitytracker.com/id?1019185" source="SECTRACK">1019185</ref>
      <ref url="http://www.securityfocus.com/bid/27234" source="BID">27234</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/505990/100/0/threaded" source="BUGTRAQ">20090821 VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486167/100/0/threaded" source="BUGTRAQ">20080110 SecurityReason - Apache (mod_proxy_ftp) Undefined Charset UTF-7 XSS Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0009.html" source="REDHAT">RHSA-2008:0009</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0008.html" source="REDHAT">RHSA-2008:0008</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0007.html" source="REDHAT">RHSA-2008:0007</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0006.html" source="REDHAT">RHSA-2008:0006</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0005.html" source="REDHAT">RHSA-2008:0005</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0004.html" source="REDHAT">RHSA-2008:0004</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:016" source="MANDRIVA">MDVSA-2008:016</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:015" source="MANDRIVA">MDVSA-2008:015</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:014" source="MANDRIVA">MDVSA-2008:014</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm</ref>
      <ref url="http://securityreason.com/securityalert/3526" source="SREASON">3526</ref>
      <ref url="http://securityreason.com/achievement_securityalert/49" source="SREASONRES">20080110 Apache (mod_proxy_ftp) Undefined Charset UTF-7 XSS Vulnerability</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200803-19.xml" source="GENTOO">GLSA-200803-19</ref>
      <ref url="http://secunia.com/advisories/35650" source="SECUNIA">35650</ref>
      <ref url="http://secunia.com/advisories/30732" source="SECUNIA">30732</ref>
      <ref url="http://secunia.com/advisories/29640" source="SECUNIA">29640</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA">29420</ref>
      <ref url="http://secunia.com/advisories/29348" source="SECUNIA">29348</ref>
      <ref url="http://secunia.com/advisories/28977" source="SECUNIA">28977</ref>
      <ref url="http://secunia.com/advisories/28749" source="SECUNIA">28749</ref>
      <ref url="http://secunia.com/advisories/28607" source="SECUNIA">28607</ref>
      <ref url="http://secunia.com/advisories/28526" source="SECUNIA">28526</ref>
      <ref url="http://secunia.com/advisories/28471" source="SECUNIA">28471</ref>
      <ref url="http://secunia.com/advisories/28467" source="SECUNIA">28467</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10812" source="OVAL">oval:org.mitre.oval:def:10812</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=130497311408250&amp;w=2" source="HP">SSRT090208</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=130497311408250&amp;w=2" source="HP">HPSBOV02683</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2" source="HP">HPSBUX02465</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2" source="HP">HPSBUX02465</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2" source="HP">HPSBUX02431</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2" source="HP">HPSBUX02431</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2009/000062.html" source="MLIST">[security-announce] 20090820 VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html" source="SUSE">SUSE-SA:2008:021</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE">APPLE-SA-2008-03-18</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.3"/>
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0006" published="2008-01-18" name="CVE-2008-0006" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in (1) X.Org Xserver before 1.4.1, and (2) the libfont and libXfont libraries on some platforms including Sun Solaris, allows context-dependent attackers to execute arbitrary code via a PCF font with a large difference between the last col and first col values in the PCF_BDF_ENCODINGS table.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27336" source="BID" patch="1">27336</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103192-1" source="SUNALERT" patch="1">103192</ref>
      <ref url="http://lists.freedesktop.org/archives/xorg/2008-January/031918.html" source="MLIST" patch="1">[xorg] 20080117 X.Org security advisory: multiple vulnerabilities in the X server</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00771.html" source="FEDORA">FEDORA-2008-0891</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00704.html" source="FEDORA">FEDORA-2008-0831</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00674.html" source="FEDORA">FEDORA-2008-0794</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00641.html" source="FEDORA">FEDORA-2008-0760</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=428044" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=428044</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39767" source="XF">xorg-pcffont-bo(39767)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/3000" source="VUPEN">ADV-2008-3000</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN">ADV-2008-0924</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0703" source="VUPEN">ADV-2008-0703</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0497/references" source="VUPEN">ADV-2008-0497</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0184" source="VUPEN">ADV-2008-0184</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0179" source="VUPEN">ADV-2008-0179</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-571-1" source="UBUNTU">USN-571-1</ref>
      <ref url="http://www.securityfocus.com/bid/27352" source="BID">27352</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0064.html" source="REDHAT">RHSA-2008:0064</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0030.html" source="REDHAT">RHSA-2008:0030</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0029.html" source="REDHAT">RHSA-2008:0029</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:024" source="MANDRIVA">MDVSA-2008:024</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:022" source="MANDRIVA">MDVSA-2008:022</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:021" source="MANDRIVA">MDVSA-2008:021</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2008-038.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2008-038.htm</ref>
      <ref url="http://securitytracker.com/id?1019232" source="SECTRACK">1019232</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200801-09.xml" source="GENTOO">GLSA-200801-09</ref>
      <ref url="http://secunia.com/advisories/32545" source="SECUNIA">32545</ref>
      <ref url="http://secunia.com/advisories/28621" source="SECUNIA" adv="1">28621</ref>
      <ref url="http://secunia.com/advisories/28592" source="SECUNIA" adv="1">28592</ref>
      <ref url="http://secunia.com/advisories/28571" source="SECUNIA" adv="1">28571</ref>
      <ref url="http://secunia.com/advisories/28550" source="SECUNIA" adv="1">28550</ref>
      <ref url="http://secunia.com/advisories/28544" source="SECUNIA" adv="1">28544</ref>
      <ref url="http://secunia.com/advisories/28542" source="SECUNIA" adv="1">28542</ref>
      <ref url="http://secunia.com/advisories/28540" source="SECUNIA" adv="1">28540</ref>
      <ref url="http://secunia.com/advisories/28536" source="SECUNIA" adv="1">28536</ref>
      <ref url="http://secunia.com/advisories/28535" source="SECUNIA" adv="1">28535</ref>
      <ref url="http://secunia.com/advisories/28532" source="SECUNIA" adv="1">28532</ref>
      <ref url="http://secunia.com/advisories/28500" source="SECUNIA" adv="1">28500</ref>
      <ref url="http://secunia.com/advisories/28273" source="SECUNIA" adv="1">28273</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10021" source="OVAL">oval:org.mitre.oval:def:10021</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00004.html" source="SUSE">SUSE-SA:2008:003</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001043.html" source="JVNDB">JVNDB-2008-001043</ref>
      <ref url="http://jvn.jp/en/jp/JVN88935101/index.html" source="JVN">JVN#88935101</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01543321" source="HP">HPSBUX02381</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01543321" source="HP">HPSBUX02381</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=204362" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=204362</ref>
      <ref url="https://issues.rpath.com/browse/RPL-2010" source="CONFIRM">https://issues.rpath.com/browse/RPL-2010</ref>
      <ref url="http://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&amp;heading=AIX61&amp;path=/200802/SECURITY/20080227/datafile112539&amp;label=AIX%20X%20server%20multiple%20vulnerabilities" source="CONFIRM">http://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&amp;heading=AIX61&amp;path=/200802/SECURITY/20080227/datafile112539&amp;label=AIX%20X%20server%20multiple%20vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487335/100/0/threaded" source="BUGTRAQ">20080130 rPSA-2008-0032-1 xorg-x11 xorg-x11-fonts xorg-x11-tools xorg-x11-xfs</ref>
      <ref url="http://www.openbsd.org/errata42.html#006_xorg" source="OPENBSD">[4.2] 20080208 006: SECURITY FIX: February 8, 2008</ref>
      <ref url="http://www.openbsd.org/errata41.html#012_xorg" source="OPENBSD">[4.1] 20080208 012: SECURITY FIX: February 8, 2008</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200805-07.xml" source="GENTOO">GLSA-200805-07</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2008-077.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2008-077.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-201230-1" source="SUNALERT">201230</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200804-05.xml" source="GENTOO">GLSA-200804-05</ref>
      <ref url="http://secunia.com/advisories/30161" source="SECUNIA">30161</ref>
      <ref url="http://secunia.com/advisories/29707" source="SECUNIA">29707</ref>
      <ref url="http://secunia.com/advisories/29622" source="SECUNIA">29622</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA">29420</ref>
      <ref url="http://secunia.com/advisories/29139" source="SECUNIA">29139</ref>
      <ref url="http://secunia.com/advisories/28941" source="SECUNIA">28941</ref>
      <ref url="http://secunia.com/advisories/28885" source="SECUNIA">28885</ref>
      <ref url="http://secunia.com/advisories/28843" source="SECUNIA">28843</ref>
      <ref url="http://secunia.com/advisories/28718" source="SECUNIA">28718</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.html" source="SUSE">SUSE-SR:2008:008</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE">APPLE-SA-2008-03-18</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris_libfont">
        <vers num=""/>
      </prod>
      <prod vendor="sun" name="solaris_libxfont">
        <vers num=""/>
      </prod>
      <prod vendor="x.org" name="xserver">
        <vers prev="1" num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0007" published="2008-02-07" name="CVE-2008-0007" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Linux kernel before 2.6.22.17, when using certain drivers that register a fault handler that does not perform range checks, allows local users to access kernel memory via an out-of-range offset.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/2222/references" source="VUPEN">ADV-2008-2222</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0445/references" source="VUPEN">ADV-2008-0445</ref>
      <ref url="http://www.ubuntu.com/usn/usn-618-1" source="UBUNTU">USN-618-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0787.html" source="REDHAT">RHSA-2008:0787</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:174" source="MANDRIVA">MDVSA-2008:174</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:112" source="MANDRIVA">MDVSA-2008:112</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.17" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.17</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1565" source="DEBIAN">DSA-1565</ref>
      <ref url="http://secunia.com/advisories/33280" source="SECUNIA">33280</ref>
      <ref url="http://secunia.com/advisories/31246" source="SECUNIA">31246</ref>
      <ref url="http://secunia.com/advisories/30769" source="SECUNIA">30769</ref>
      <ref url="http://secunia.com/advisories/30116" source="SECUNIA">30116</ref>
      <ref url="http://secunia.com/advisories/30112" source="SECUNIA">30112</ref>
      <ref url="http://secunia.com/advisories/30110" source="SECUNIA">30110</ref>
      <ref url="http://secunia.com/advisories/30018" source="SECUNIA">30018</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9412" source="OVAL">oval:org.mitre.oval:def:9412</ref>
      <ref url="http://lkml.org/lkml/2008/2/6/457" source="MLIST">[linux-kernel] 20080206 [patch 60/73] vm audit: add VM_DONTEXPAND to mmap for drivers that need it (CVE-2008-0007)</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2008/000023.html" source="MLIST">[Security-announce] 20080728 VMSA-2008-00011 Updated ESX service console packages for Samba and vmnix</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00002.html" source="SUSE">SUSE-SA:2008:006</ref>
      <ref url="http://www.securityfocus.com/bid/27705" source="BID">27705</ref>
      <ref url="http://www.securityfocus.com/bid/27686" source="BID">27686</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487808/100/0/threaded" source="BUGTRAQ">20080208 rPSA-2008-0048-1 kernel</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0237.html" source="REDHAT">RHSA-2008:0237</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0233.html" source="REDHAT">RHSA-2008:0233</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0211.html" source="REDHAT">RHSA-2008:0211</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:072" source="MANDRIVA">MDVSA-2008:072</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:044" source="MANDRIVA">MDVSA-2008:044</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1504" source="DEBIAN">DSA-1504</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1503" source="DEBIAN">DSA-1503</ref>
      <ref url="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0048" source="CONFIRM">http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0048</ref>
      <ref url="http://securitytracker.com/id?1019357" source="SECTRACK">1019357</ref>
      <ref url="http://secunia.com/advisories/29570" source="SECUNIA">29570</ref>
      <ref url="http://secunia.com/advisories/29058" source="SECUNIA">29058</ref>
      <ref url="http://secunia.com/advisories/28826" source="SECUNIA">28826</ref>
      <ref url="http://secunia.com/advisories/28806" source="SECUNIA">28806</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00007.html" source="SUSE">SUSE-SA:2008:017</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.6.22.16"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0008" published="2008-01-28" name="CVE-2008-0008" modified="2011-08-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The pa_drop_root function in PulseAudio 0.9.8, and a certain 0.9.9 build, does not check return values from (1) setresuid, (2) setreuid, (3) setuid, and (4) seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail via attacks such as resource exhaustion.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00869.html" source="FEDORA">FEDORA-2008-0994</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00852.html" source="FEDORA">FEDORA-2008-0963</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=425481" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=425481</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=347822" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=347822</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39992" source="XF">pulseaudio-padroproot-privilege-escalation(39992)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0283" source="VUPEN" adv="1">ADV-2008-0283</ref>
      <ref url="http://www.ubuntu.com/usn/usn-573-1" source="UBUNTU">USN-573-1</ref>
      <ref url="http://www.securityfocus.com/bid/27449" source="BID">27449</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:027" source="MANDRIVA">MDVSA-2008:027</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1476" source="DEBIAN">DSA-1476</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200802-07.xml" source="GENTOO">GLSA-200802-07</ref>
      <ref url="http://secunia.com/advisories/28952" source="SECUNIA" adv="1">28952</ref>
      <ref url="http://secunia.com/advisories/28738" source="SECUNIA" adv="1">28738</ref>
      <ref url="http://secunia.com/advisories/28623" source="SECUNIA" adv="1">28623</ref>
      <ref url="http://secunia.com/advisories/28608" source="SECUNIA" adv="1">28608</ref>
      <ref url="http://pulseaudio.org/changeset/2100" source="CONFIRM">http://pulseaudio.org/changeset/2100</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=207214" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=207214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pulseaudio" name="pulseaudio">
        <vers num="0.9.6"/>
        <vers num="0.9.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2008-0009" published="2008-02-12" name="CVE-2008-0009" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The vmsplice_to_user function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which might allow local users to access arbitrary kernel memory locations.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=431206" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=431206</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0487/references" source="VUPEN">ADV-2008-0487</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1</ref>
      <ref url="http://isec.pl/vulnerabilities/isec-0026-vmsplice_to_kernel.txt" source="MISC">http://isec.pl/vulnerabilities/isec-0026-vmsplice_to_kernel.txt</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00255.html" source="FEDORA">FEDORA-2008-1423</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00254.html" source="FEDORA">FEDORA-2008-1422</ref>
      <ref url="http://www.securityfocus.com/bid/27799" source="BID">27799</ref>
      <ref url="http://www.securityfocus.com/bid/27704" source="BID">27704</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487982/100/0/threaded" source="BUGTRAQ">20080212 CSA-L03: Linux kernel vmsplice unchecked user-pointer dereference</ref>
      <ref url="http://secunia.com/advisories/28896" source="SECUNIA">28896</ref>
      <ref url="http://secunia.com/advisories/28835" source="SECUNIA">28835</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.22" edition="rc6"/>
        <vers num="2.6.22.1"/>
        <vers num="2.6.22.16"/>
        <vers num="2.6.22.3"/>
        <vers num="2.6.22.4"/>
        <vers num="2.6.22.5"/>
        <vers num="2.6.22.6"/>
        <vers num="2.6.22.7"/>
        <vers num="2.6.23" edition="rc1"/>
        <vers num="2.6.23" edition="rc2"/>
        <vers num="2.6.23.1"/>
        <vers num="2.6.23.14"/>
        <vers num="2.6.23.2"/>
        <vers num="2.6.23.3"/>
        <vers num="2.6.23.4"/>
        <vers num="2.6.23.5"/>
        <vers num="2.6.23.6"/>
        <vers num="2.6.23.7"/>
        <vers num="2.6.23.9"/>
        <vers num="2.6.24" edition="rc2"/>
        <vers num="2.6.24" edition="rc3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2008-0010" published="2008-02-12" name="CVE-2008-0010" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The copy_from_user_mmap_sem function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which allow local users to read from arbitrary kernel memory locations.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0487/references" source="VUPEN">ADV-2008-0487</ref>
      <ref url="http://www.milw0rm.com/exploits/5093" source="MILW0RM">5093</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1</ref>
      <ref url="http://isec.pl/vulnerabilities/isec-0026-vmsplice_to_kernel.txt" source="MISC">http://isec.pl/vulnerabilities/isec-0026-vmsplice_to_kernel.txt</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00255.html" source="FEDORA">FEDORA-2008-1423</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00254.html" source="FEDORA">FEDORA-2008-1422</ref>
      <ref url="http://www.securityfocus.com/bid/27796" source="BID">27796</ref>
      <ref url="http://www.securityfocus.com/bid/27704" source="BID">27704</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487982/100/0/threaded" source="BUGTRAQ">20080212 CSA-L03: Linux kernel vmsplice unchecked user-pointer dereference</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1494" source="DEBIAN">DSA-1494</ref>
      <ref url="http://secunia.com/advisories/28896" source="SECUNIA">28896</ref>
      <ref url="http://secunia.com/advisories/28875" source="SECUNIA">28875</ref>
      <ref url="http://secunia.com/advisories/28835" source="SECUNIA">28835</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.22" edition="rc6"/>
        <vers num="2.6.22.1"/>
        <vers num="2.6.22.16"/>
        <vers num="2.6.22.3"/>
        <vers num="2.6.22.4"/>
        <vers num="2.6.22.5"/>
        <vers num="2.6.22.6"/>
        <vers num="2.6.22.7"/>
        <vers num="2.6.23" edition="rc1"/>
        <vers num="2.6.23" edition="rc2"/>
        <vers num="2.6.23.1"/>
        <vers num="2.6.23.14"/>
        <vers num="2.6.23.2"/>
        <vers num="2.6.23.3"/>
        <vers num="2.6.23.4"/>
        <vers num="2.6.23.5"/>
        <vers num="2.6.23.6"/>
        <vers num="2.6.23.7"/>
        <vers num="2.6.23.9"/>
        <vers num="2.6.24" edition="rc2"/>
        <vers num="2.6.24" edition="rc3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0011" published="2008-06-11" name="CVE-2008-0011" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft DirectX 8.1 through 9.0c, and DirectX on Microsoft XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, does not properly perform MJPEG error checking, which allows remote attackers to execute arbitrary code via a crafted MJPEG stream in a (1) AVI or (2) ASF file, aka the "MJPEG Decoder Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-162B.html" source="CERT">TA08-162B</ref>
      <ref url="http://www.securityfocus.com/bid/29581" source="BID" patch="1">29581</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-033.mspx" source="MS" patch="1">MS08-033</ref>
      <ref url="http://securitytracker.com/id?1020222" source="SECTRACK" patch="1">1020222</ref>
      <ref url="http://secunia.com/advisories/30579" source="SECUNIA" patch="1" adv="1">30579</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1780" source="VUPEN">ADV-2008-1780</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5236" source="OVAL">oval:org.mitre.oval:def:5236</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=121380194923597&amp;w=2" source="HP">SSRT080087</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=121380194923597&amp;w=2" source="HP">SSRT080087</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="directx">
        <vers num="10.0"/>
        <vers num="7.0"/>
        <vers num="8.1"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0012" published="2008-11-17" name="CVE-2008-0012" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to the product's configuration, a different vulnerability than CVE-2008-0013 and CVE-2008-0014.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/768681" source="CERT-VN">VU#768681</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39918" source="XF">application-rpc-config1-bo(39918)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/3127" source="VUPEN">ADV-2008-3127</ref>
      <ref url="http://www.securityfocus.com/bid/32261" source="BID">32261</ref>
      <ref url="http://www.iss.net/threats/310.html" source="ISS">20081111 Trend Micro ServerProtect [PROCEDURE NAME REDACTED] Heap Overflows (3)</ref>
      <ref url="http://secunia.com/advisories/32618" source="SECUNIA" adv="1">32618</ref>
      <ref url="http://blogs.iss.net/archive/trend.html" source="MISC">http://blogs.iss.net/archive/trend.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="serverprotect">
        <vers num="5.58"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0013" published="2008-11-17" name="CVE-2008-0013" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to the product's configuration, a different vulnerability than CVE-2008-0012 and CVE-2008-0014.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/768681" source="CERT-VN">VU#768681</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39919" source="XF">application-rpc-config2-bo(39919)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/3127" source="VUPEN">ADV-2008-3127</ref>
      <ref url="http://www.securityfocus.com/bid/32261" source="BID">32261</ref>
      <ref url="http://www.iss.net/threats/310.html" source="ISS">20081111 Trend Micro ServerProtect [PROCEDURE NAME REDACTED] Heap Overflows (3)</ref>
      <ref url="http://secunia.com/advisories/32618" source="SECUNIA" adv="1">32618</ref>
      <ref url="http://blogs.iss.net/archive/trend.html" source="MISC">http://blogs.iss.net/archive/trend.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="serverprotect">
        <vers num="5.58"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0014" published="2008-11-17" name="CVE-2008-0014" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to the product's configuration, a different vulnerability than CVE-2008-0012 and CVE-2008-0013.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/768681" source="CERT-VN">VU#768681</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39920" source="XF">application-rpc-config3-bo(39920)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/3127" source="VUPEN">ADV-2008-3127</ref>
      <ref url="http://www.securityfocus.com/bid/32261" source="BID">32261</ref>
      <ref url="http://www.iss.net/threats/310.html" source="ISS">20081111 Trend Micro ServerProtect [PROCEDURE NAME REDACTED] Heap Overflows (3)</ref>
      <ref url="http://secunia.com/advisories/32618" source="SECUNIA" adv="1">32618</ref>
      <ref url="http://blogs.iss.net/archive/trend.html" source="MISC">http://blogs.iss.net/archive/trend.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="serverprotect">
        <vers num="5.58"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0015" published="2009-07-07" name="CVE-2008-0015" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted web page, as exploited in the wild in July 2009, aka "Microsoft Video ActiveX Control Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-223A.html" source="CERT">TA09-223A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-195A.html" source="CERT">TA09-195A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-187A.html" source="CERT">TA09-187A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/180513" source="CERT-VN">VU#180513</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2232" source="VUPEN">ADV-2009-2232</ref>
      <ref url="http://www.securitytracker.com/id?1022514" source="SECTRACK">1022514</ref>
      <ref url="http://www.securityfocus.com/bid/35585" source="BID">35585</ref>
      <ref url="http://www.securityfocus.com/bid/35558" source="BID">35558</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-037.mspx" source="MS">MS09-037</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-032.mspx" source="MS">MS09-032</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/972890.mspx" source="CONFIRM" adv="1">http://www.microsoft.com/technet/security/advisory/972890.mspx</ref>
      <ref url="http://www.iss.net/threats/329.html" source="ISS">20090706 Multiple Microsoft Video Control ActiveX Remote Code Execution Vulnerabilities</ref>
      <ref url="http://www.csis.dk/dk/nyheder/nyheder.asp?tekstID=799" source="MISC">http://www.csis.dk/dk/nyheder/nyheder.asp?tekstID=799</ref>
      <ref url="http://secunia.com/advisories/36187" source="SECUNIA">36187</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7436" source="OVAL">oval:org.mitre.oval:def:7436</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6363" source="OVAL">oval:org.mitre.oval:def:6363</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6333" source="OVAL">oval:org.mitre.oval:def:6333</ref>
      <ref url="http://osvdb.org/55651" source="OSVDB">55651</ref>
      <ref url="http://isc.sans.org/diary.html?storyid=6733" source="MISC">http://isc.sans.org/diary.html?storyid=6733</ref>
      <ref url="http://blogs.technet.com/srd/archive/2009/08/11/ms09-037-why-we-are-using-cve-s-already-used-in-ms09-035.aspx" source="MISC">http://blogs.technet.com/srd/archive/2009/08/11/ms09-037-why-we-are-using-cve-s-already-used-in-ms09-035.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
        <vers num="-" edition="sp2:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:professional_x64"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0016" published="2008-09-24" name="CVE-2008-0016" modified="2012-10-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to execute arbitrary code via a crafted UTF-8 URL in a link.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=443288" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=443288</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-September/msg01403.html" source="FEDORA">FEDORA-2008-8429</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-September/msg01384.html" source="FEDORA">FEDORA-2008-8401</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=451617" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=451617</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0977" source="VUPEN">ADV-2009-0977</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/2661" source="VUPEN">ADV-2008-2661</ref>
      <ref url="http://www.ubuntu.com/usn/usn-645-2" source="UBUNTU">USN-645-2</ref>
      <ref url="http://www.ubuntu.com/usn/usn-645-1" source="UBUNTU">USN-645-1</ref>
      <ref url="http://www.securitytracker.com/id?1020913" source="SECTRACK">1020913</ref>
      <ref url="http://www.securityfocus.com/bid/31397" source="BID">31397</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0908.html" source="REDHAT">RHSA-2008:0908</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0882.html" source="REDHAT">RHSA-2008:0882</ref>
      <ref url="http://www.mozilla.org/security/announce/2008/mfsa2008-37.html" source="CONFIRM">http://www.mozilla.org/security/announce/2008/mfsa2008-37.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:206" source="MANDRIVA">MDVSA-2008:206</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:205" source="MANDRIVA">MDVSA-2008:205</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1697" source="DEBIAN">DSA-1697</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1696" source="DEBIAN">DSA-1696</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1669" source="DEBIAN">DSA-1669</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1649" source="DEBIAN">DSA-1649</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1" source="SUNALERT">256408</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2008&amp;m=slackware-security.412123" source="SLACKWARE">SSA:2008-270-01</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2008&amp;m=slackware-security.405232" source="SLACKWARE">SSA:2008-269-01</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2008&amp;m=slackware-security.379422" source="SLACKWARE">SSA:2008-269-02</ref>
      <ref url="http://secunia.com/advisories/34501" source="SECUNIA">34501</ref>
      <ref url="http://secunia.com/advisories/33434" source="SECUNIA">33434</ref>
      <ref url="http://secunia.com/advisories/33433" source="SECUNIA">33433</ref>
      <ref url="http://secunia.com/advisories/32845" source="SECUNIA">32845</ref>
      <ref url="http://secunia.com/advisories/32196" source="SECUNIA">32196</ref>
      <ref url="http://secunia.com/advisories/32185" source="SECUNIA">32185</ref>
      <ref url="http://secunia.com/advisories/32144" source="SECUNIA">32144</ref>
      <ref url="http://secunia.com/advisories/32092" source="SECUNIA">32092</ref>
      <ref url="http://secunia.com/advisories/32082" source="SECUNIA">32082</ref>
      <ref url="http://secunia.com/advisories/32044" source="SECUNIA">32044</ref>
      <ref url="http://secunia.com/advisories/32042" source="SECUNIA">32042</ref>
      <ref url="http://secunia.com/advisories/32012" source="SECUNIA">32012</ref>
      <ref url="http://secunia.com/advisories/32010" source="SECUNIA">32010</ref>
      <ref url="http://secunia.com/advisories/31985" source="SECUNIA">31985</ref>
      <ref url="http://secunia.com/advisories/31984" source="SECUNIA">31984</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11579" source="OVAL">oval:org.mitre.oval:def:11579</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00005.html" source="SUSE">SUSE-SA:2008:050</ref>
      <ref url="http://download.novell.com/Download?buildid=WZXONb-tqBw~" source="CONFIRM">http://download.novell.com/Download?buildid=WZXONb-tqBw~</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10"/>
        <vers num="0.10.1"/>
        <vers num="0.8"/>
        <vers num="0.9" edition="rc"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9_rc"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="1.8"/>
        <vers num="2.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers prev="1" num="2.0.0.16"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition=""/>
        <vers num="1.0" edition=":dev"/>
        <vers num="1.0" edition=":alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.0.99"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers prev="1" num="1.1.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0017" published="2008-11-13" name="CVE-2008-0017" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP index response with a crafted 200 header, which triggers memory corruption and a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-319A.html" source="CERT">TA08-319A</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00385.html" source="FEDORA">FEDORA-2008-9669</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00366.html" source="FEDORA">FEDORA-2008-9667</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=443299" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=443299</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0977" source="VUPEN">ADV-2009-0977</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/3146" source="VUPEN">ADV-2008-3146</ref>
      <ref url="http://www.securitytracker.com/id?1021185" source="SECTRACK">1021185</ref>
      <ref url="http://www.securityfocus.com/bid/32281" source="BID">32281</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0978.html" source="REDHAT">RHSA-2008:0978</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0977.html" source="REDHAT">RHSA-2008:0977</ref>
      <ref url="http://www.mozilla.org/security/announce/2008/mfsa2008-54.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2008/mfsa2008-54.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:230" source="MANDRIVA">MDVSA-2008:230</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:228" source="MANDRIVA">MDVSA-2008:228</ref>
      <ref url="http://www.iss.net/threats/311.html" source="ISS">20081113 Mozilla Unchecked Allocation Remote Code Execution</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1697" source="DEBIAN">DSA-1697</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1671" source="DEBIAN">DSA-1671</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1669" source="DEBIAN">DSA-1669</ref>
      <ref url="http://ubuntu.com/usn/usn-667-1" source="UBUNTU">USN-667-1</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1" source="SUNALERT">256408</ref>
      <ref url="http://secunia.com/advisories/34501" source="SECUNIA">34501</ref>
      <ref url="http://secunia.com/advisories/33433" source="SECUNIA">33433</ref>
      <ref url="http://secunia.com/advisories/32853" source="SECUNIA">32853</ref>
      <ref url="http://secunia.com/advisories/32845" source="SECUNIA">32845</ref>
      <ref url="http://secunia.com/advisories/32778" source="SECUNIA">32778</ref>
      <ref url="http://secunia.com/advisories/32721" source="SECUNIA">32721</ref>
      <ref url="http://secunia.com/advisories/32714" source="SECUNIA">32714</ref>
      <ref url="http://secunia.com/advisories/32713" source="SECUNIA">32713</ref>
      <ref url="http://secunia.com/advisories/32695" source="SECUNIA">32695</ref>
      <ref url="http://secunia.com/advisories/32694" source="SECUNIA">32694</ref>
      <ref url="http://secunia.com/advisories/32693" source="SECUNIA">32693</ref>
      <ref url="http://secunia.com/advisories/32684" source="SECUNIA">32684</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11005" source="OVAL">oval:org.mitre.oval:def:11005</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.html" source="SUSE">SUSE-SA:2008:055</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="2.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers prev="1" num="2.0.0.17"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers prev="1" num="3.0.3"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0020" published="2009-07-07" name="CVE-2008-0020" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Load method in the IPersistStreamInit interface in the Active Template Library (ATL), as used in the Microsoft Video ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via unknown vectors that trigger memory corruption, aka "ATL Header Memcopy Vulnerability," a different vulnerability than CVE-2008-0015.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-223A.html" source="CERT">TA09-223A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2232" source="VUPEN" patch="1" adv="1">ADV-2009-2232</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-037.mspx" source="MS" patch="1" adv="1">MS09-037</ref>
      <ref url="http://www.securitytracker.com/id?1022712" source="SECTRACK">1022712</ref>
      <ref url="http://www.iss.net/threats/329.html" source="ISS">20090706 Multiple Microsoft Video Control ActiveX Remote Code Execution Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/36187" source="SECUNIA" adv="1">36187</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5850" source="OVAL">oval:org.mitre.oval:def:5850</ref>
      <ref url="http://blogs.technet.com/srd/archive/2009/08/11/ms09-037-why-we-are-using-cve-s-already-used-in-ms09-035.aspx" source="MISC">http://blogs.technet.com/srd/archive/2009/08/11/ms09-037-why-we-are-using-cve-s-already-used-in-ms09-035.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
        <vers num="-" edition="sp2:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:professional_x64"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0026" published="2008-02-14" name="CVE-2008-0026" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 before 5.1(3a) and 6.0/6.1 before 6.1(1a) allows remote authenticated users to execute arbitrary SQL commands via the key parameter to the (1) admin and (2) user interface pages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/40484" source="XF">cucm-interface-sql-injection(40484)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0542" source="VUPEN" adv="1">ADV-2008-0542</ref>
      <ref url="http://www.securitytracker.com/id?1019404" source="SECTRACK">1019404</ref>
      <ref url="http://www.securityfocus.com/bid/27775" source="BID">27775</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7c.shtml" source="CISCO">20080213 SQL injection in Cisco Unified Communications Manager</ref>
      <ref url="http://secunia.com/advisories/28932" source="SECUNIA" adv="1">28932</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="unified_callmanager">
        <vers num="5.0"/>
        <vers num="5.0(1)"/>
        <vers num="5.0(2)"/>
        <vers num="5.0(3)"/>
        <vers num="5.0(3a)"/>
        <vers num="5.0(4)"/>
        <vers num="5.0_4a"/>
        <vers num="5.1"/>
        <vers num="6.0"/>
      </prod>
      <prod vendor="cisco" name="unified_communications_manager">
        <vers num="5.0"/>
        <vers num="5.0_1"/>
        <vers num="5.0_2"/>
        <vers num="5.0_3"/>
        <vers num="5.0_3a"/>
        <vers num="5.0_4"/>
        <vers num="5.0_4a"/>
        <vers num="5.0_4a_su1"/>
        <vers num="6.0"/>
        <vers num="6.0_1"/>
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0027" published="2008-01-16" name="CVE-2008-0027" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM) 4.2 before 4.2(3)SR3 and 4.3 before 4.3(1)SR1, and CallManager 4.0 and 4.1 before 4.1(3)SR5c, allows remote attackers to cause a denial of service or execute arbitrary code via a long request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080932c61.shtml" source="CISCO" patch="1">20080116 Cisco Unified Communications Manager CTL Provider Heap Overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39704" source="XF">cisco-cucm-ctl-bo(39704)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0171" source="VUPEN">ADV-2008-0171</ref>
      <ref url="http://www.securityfocus.com/bid/27313" source="BID">27313</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486432/100/0/threaded" source="BUGTRAQ">20080116 TPTI-08-02: Cisco Call Manager CTLProvider Heap Overflow Vulnerability</ref>
      <ref url="http://dvlabs.tippingpoint.com/advisory/TPTI-08-02" source="MISC">http://dvlabs.tippingpoint.com/advisory/TPTI-08-02</ref>
      <ref url="http://www.securitytracker.com/id?1019223" source="SECTRACK">1019223</ref>
      <ref url="http://securityreason.com/securityalert/3551" source="SREASON">3551</ref>
      <ref url="http://secunia.com/advisories/28530" source="SECUNIA">28530</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="unified_callmanager">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.1(3)sr4"/>
        <vers num="4.1(3)sr5"/>
        <vers num="4.1(3)sr5b"/>
      </prod>
      <prod vendor="cisco" name="unified_communications_manager">
        <vers num="4.2"/>
        <vers num="4.2.3sr2"/>
        <vers num="4.2.3sr2b"/>
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0028" published="2008-01-23" name="CVE-2008-0028" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco PIX 500 Series Security Appliance and 5500 Series Adaptive Security Appliance (ASA) before 7.2(3)6 and 8.0(3), when the Time-to-Live (TTL) decrement feature is enabled, allows remote attackers to cause a denial of service (device reload) via a crafted IP packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39862" source="XF">pix-asa-ttl-dos(39862)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0259" source="VUPEN" adv="1">ADV-2008-0259</ref>
      <ref url="http://www.securitytracker.com/id?1019263" source="SECTRACK">1019263</ref>
      <ref url="http://www.securitytracker.com/id?1019262" source="SECTRACK">1019262</ref>
      <ref url="http://www.securityfocus.com/bid/27418" source="BID">27418</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20080123-asa.shtml" source="CISCO">20080123 Cisco PIX and ASA Time-to-Live Vulnerability</ref>
      <ref url="http://secunia.com/advisories/28625" source="SECUNIA" adv="1">28625</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="5500_adaptive_security_appliance">
        <vers prev="1" num="7.2" edition="2"/>
      </prod>
      <prod vendor="cisco" name="5500_series_adaptive_security_appliance">
        <vers prev="1" num="8.0" edition="2"/>
      </prod>
      <prod vendor="cisco" name="pix_firewall">
        <vers prev="1" num="7.2(2)"/>
        <vers prev="1" num="8.0(2)"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0029" published="2008-01-23" name="CVE-2008-0029" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Cisco Application Velocity System (AVS) before 5.1.0 is installed with default passwords for some system accounts, which allows remote attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0260" source="VUPEN">ADV-2008-0260</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20080123-avs.shtml" source="CISCO">20080123 Default Passwords in the Application Velocity System</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39860" source="XF">ciscoavs-default-password-admin-account(39860)</ref>
      <ref url="http://www.securitytracker.com/id?1019259" source="SECTRACK">1019259</ref>
      <ref url="http://www.securityfocus.com/bid/27421" source="BID">27421</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="application_velocity_system">
        <vers prev="1" num="5.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0031" published="2008-01-15" name="CVE-2008-0031" modified="2011-09-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Apple QuickTime before 7.4 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted Sorenson 3 video file, which triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-016A.html" source="CERT">TA08-016A</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0148" source="VUPEN">ADV-2008-0148</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Jan/msg00001.html" source="APPLE">APPLE-SA-2008-01-15</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307301" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307301</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39695" source="XF">quicktime-sorenson-code-execution(39695)</ref>
      <ref url="http://www.securitytracker.com/id?1019221" source="SECTRACK">1019221</ref>
      <ref url="http://www.securityfocus.com/bid/27298" source="BID">27298</ref>
      <ref url="http://secunia.com/advisories/28502" source="SECUNIA">28502</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers prev="1" num="7.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0032" published="2008-01-15" name="CVE-2008-0032" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Apple QuickTime before 7.4 allows remote attackers to execute arbitrary code via a movie file containing a Macintosh Resource record with a modified length value in the resource header, which triggers heap corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-016A.html" source="CERT">TA08-016A</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=642" source="IDEFENSE" patch="1">20080115 Apple QuickTime Macintosh Resource Processing Heap Corruption Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0148" source="VUPEN">ADV-2008-0148</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Jan/msg00001.html" source="APPLE">APPLE-SA-2008-01-15</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307301" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307301</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39696" source="XF">quicktime-macintosh-code-execution(39696)</ref>
      <ref url="http://www.securitytracker.com/id?1019221" source="SECTRACK">1019221</ref>
      <ref url="http://www.securityfocus.com/bid/27301" source="BID">27301</ref>
      <ref url="http://secunia.com/advisories/28502" source="SECUNIA">28502</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers prev="1" num="7.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0033" published="2008-01-15" name="CVE-2008-0033" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Apple QuickTime before 7.4 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a movie file with Image Descriptor (IDSC) atoms containing an invalid atom size, which triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-016A.html" source="CERT">TA08-016A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39697" source="XF">quicktime-idsc-code-execution(39697)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0148" source="VUPEN" adv="1">ADV-2008-0148</ref>
      <ref url="http://www.securitytracker.com/id?1019221" source="SECTRACK">1019221</ref>
      <ref url="http://www.securityfocus.com/bid/27299" source="BID">27299</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486413/100/0/threaded" source="BUGTRAQ">20080115 TPTI-08-01: Apple Quicktime Image File IDSC Atom Memory Corruption Vulnerability</ref>
      <ref url="http://secunia.com/advisories/28502" source="SECUNIA" adv="1">28502</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Jan/msg00001.html" source="APPLE">APPLE-SA-2008-01-15</ref>
      <ref url="http://dvlabs.tippingpoint.com/advisory/TPTI-08-01" source="MISC">http://dvlabs.tippingpoint.com/advisory/TPTI-08-01</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307301" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307301</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers prev="1" num="7.3.1.70"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0034" published="2008-01-15" name="CVE-2008-0034" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in Passcode Lock in Apple iPhone 1.0 through 1.1.2 allows users with physical access to execute applications without entering the passcode via vectors related to emergency calls.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0147" source="VUPEN">ADV-2008-0147</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Jan/msg00000.html" source="APPLE">APPLE-SA-2008-01-15</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307302" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307302</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39701" source="XF">iphone-passcode-lock-security-bypass(39701)</ref>
      <ref url="http://www.securitytracker.com/id?1019219" source="SECTRACK">1019219</ref>
      <ref url="http://www.securityfocus.com/bid/27297" source="BID">27297</ref>
      <ref url="http://secunia.com/advisories/28497" source="SECUNIA">28497</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.02"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0035" published="2008-01-15" name="CVE-2008-0035" modified="2011-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Foundation, as used in Apple iPhone 1.0 through 1.1.2, iPod touch 1.1 through 1.1.2, and Mac OS X 10.5 through 10.5.1, allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted URL that triggers memory corruption in Safari.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-043B.html" source="CERT">TA08-043B</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39700" source="XF">iphone-ipod-foundation-code-execution(39700)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0495/references" source="VUPEN" adv="1">ADV-2008-0495</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0147" source="VUPEN" adv="1">ADV-2008-0147</ref>
      <ref url="http://www.securitytracker.com/id?1019220" source="SECTRACK">1019220</ref>
      <ref url="http://www.securityfocus.com/bid/27296" source="BID">27296</ref>
      <ref url="http://secunia.com/advisories/28891" source="SECUNIA" adv="1">28891</ref>
      <ref url="http://secunia.com/advisories/28497" source="SECUNIA" adv="1">28497</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Jan/msg00000.html" source="APPLE">APPLE-SA-2008-01-15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html" source="APPLE">APPLE-SA-2008-02-11</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307430" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307430</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307302" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307302</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0036" published="2008-01-15" name="CVE-2008-0036" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in Apple QuickTime before 7.4 allows remote attackers to execute arbitrary code via a crafted compressed PICT image, which triggers the overflow during decoding.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-016A.html" source="CERT">TA08-016A</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/2064/references" source="VUPEN">ADV-2008-2064</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0148" source="VUPEN">ADV-2008-0148</ref>
      <ref url="http://secunia.com/advisories/31034" source="SECUNIA">31034</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Jan/msg00001.html" source="APPLE">APPLE-SA-2008-01-15</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008//Jul/msg00000.html" source="APPLE">APPLE-SA-2008-07-10</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307301" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307301</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39698" source="XF">quicktime-pict-bo(39698)</ref>
      <ref url="http://www.securitytracker.com/id?1019221" source="SECTRACK">1019221</ref>
      <ref url="http://www.securityfocus.com/bid/27300" source="BID">27300</ref>
      <ref url="http://secunia.com/advisories/28502" source="SECUNIA">28502</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers prev="1" num="7.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0037" published="2008-02-12" name="CVE-2008-0037" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">X11 in Apple Mac OS X 10.5 through 10.5.1 does not properly handle when the "Allow connections from network client" preference is disabled, which allows remote attackers to bypass intended access restrictions and connect to the X server.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-043B.html" source="CERT">TA08-043B</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html" source="APPLE" patch="1">APPLE-SA-2008-02-11</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0495/references" source="VUPEN">ADV-2008-0495</ref>
      <ref url="http://www.securitytracker.com/id?1019365" source="SECTRACK">1019365</ref>
      <ref url="http://www.securityfocus.com/bid/27736" source="BID">27736</ref>
      <ref url="http://secunia.com/advisories/28891" source="SECUNIA">28891</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307430" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307430</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5"/>
        <vers num="10.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2008-0038" published="2008-02-12" name="CVE-2008-0038" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">Launch Services in Apple Mac OS X 10.5 through 10.5.1 allows an uninstalled application to be launched if it is in a Time Machine backup, which might allow local users to bypass intended security restrictions or exploit vulnerabilities in the application.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-043B.html" source="CERT">TA08-043B</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html" source="APPLE" patch="1">APPLE-SA-2008-02-11</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0495/references" source="VUPEN">ADV-2008-0495</ref>
      <ref url="http://www.securitytracker.com/id?1019360" source="SECTRACK">1019360</ref>
      <ref url="http://www.securityfocus.com/bid/27736" source="BID">27736</ref>
      <ref url="http://secunia.com/advisories/28891" source="SECUNIA">28891</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307430" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307430</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5"/>
        <vers num="10.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0039" published="2008-02-12" name="CVE-2008-0039" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Mail in Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary commands via a crafted file:// URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-043B.html" source="CERT">TA08-043B</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html" source="APPLE" patch="1">APPLE-SA-2008-02-11</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0495/references" source="VUPEN">ADV-2008-0495</ref>
      <ref url="http://www.securitytracker.com/id?1019361" source="SECTRACK">1019361</ref>
      <ref url="http://www.securityfocus.com/bid/27736" source="BID">27736</ref>
      <ref url="http://secunia.com/advisories/28891" source="SECUNIA">28891</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307430" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307430</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mail">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0040" published="2008-02-12" name="CVE-2008-0040" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in NFS in Apple Mac OS X 10.5 through 10.5.1 allows remote attackers to cause a denial of service (system shutdown) or execute arbitrary code via unknown vectors related to mbuf chains that trigger memory corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-043B.html" source="CERT">TA08-043B</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html" source="APPLE" patch="1">APPLE-SA-2008-02-11</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0495/references" source="VUPEN">ADV-2008-0495</ref>
      <ref url="http://www.securitytracker.com/id?1019362" source="SECTRACK">1019362</ref>
      <ref url="http://www.securityfocus.com/bid/27736" source="BID">27736</ref>
      <ref url="http://secunia.com/advisories/28891" source="SECUNIA">28891</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307430" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307430</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5"/>
        <vers num="10.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0041" published="2008-02-12" name="CVE-2008-0041" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Parental Controls in Apple Mac OS X 10.5 through 10.5.1 contacts www.apple.com "when a website is unblocked," which allows remote attackers to determine when a system is running Parental Controls.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-043B.html" source="CERT">TA08-043B</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html" source="APPLE" patch="1">APPLE-SA-2008-02-11</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0495/references" source="VUPEN">ADV-2008-0495</ref>
      <ref url="http://www.securitytracker.com/id?1019363" source="SECTRACK">1019363</ref>
      <ref url="http://www.securityfocus.com/bid/27736" source="BID">27736</ref>
      <ref url="http://secunia.com/advisories/28891" source="SECUNIA">28891</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307430" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307430</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5"/>
        <vers num="10.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0042" published="2008-02-12" name="CVE-2008-0042" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Argument injection vulnerability in Terminal.app in Terminal in Apple Mac OS X 10.4.11 and 10.5 through 10.5.1 allows remote attackers to execute arbitrary code via unspecified URL schemes.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-043B.html" source="CERT">TA08-043B</ref>
      <ref url="http://www.kb.cert.org/vuls/id/774345" source="CERT-VN">VU#774345</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html" source="APPLE" patch="1">APPLE-SA-2008-02-11</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0495/references" source="VUPEN">ADV-2008-0495</ref>
      <ref url="http://www.securitytracker.com/id?1019364" source="SECTRACK">1019364</ref>
      <ref url="http://www.securityfocus.com/bid/27736" source="BID">27736</ref>
      <ref url="http://secunia.com/advisories/28891" source="SECUNIA">28891</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307430" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307430</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
        <vers num="10.5"/>
        <vers num="10.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0043" published="2008-02-07" name="CVE-2008-0043" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Format string vulnerability in Apple iPhoto before 7.1.2 allows remote attackers to execute arbitrary code via photocast subscriptions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Feb/msg00000.html" source="APPLE" patch="1">APPLE-SA-2008-02-05</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0428/references" source="VUPEN">ADV-2008-0428</ref>
      <ref url="http://www.securitytracker.com/id?1019307" source="SECTRACK">1019307</ref>
      <ref url="http://secunia.com/advisories/28805" source="SECUNIA" adv="1">28805</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307398" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307398</ref>
      <ref url="http://www.securityfocus.com/bid/27636" source="BID">27636</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphoto">
        <vers prev="1" num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0044" published="2008-03-18" name="CVE-2008-0044" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Multiple buffer overflows in AFP Client in Apple Mac OS X 10.4.11 and 10.5.2 allow remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted afp:// URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" source="CERT">TA08-079A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE" patch="1">APPLE-SA-2008-03-18</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41319" source="XF">macos-afpclient-bo(41319)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN">ADV-2008-0924</ref>
      <ref url="http://www.securitytracker.com/id?1019640" source="SECTRACK">1019640</ref>
      <ref url="http://www.securityfocus.com/bid/28320" source="BID">28320</ref>
      <ref url="http://www.securityfocus.com/bid/28304" source="BID">28304</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA">29420</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
        <vers num="10.5.2"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
        <vers num="10.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0045" published="2008-03-18" name="CVE-2008-0045" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in AFP Server in Apple Mac OS X 10.4.11 allows remote attackers to bypass cross-realm authentication via unknown manipulations of Kerberos principal realm names.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" source="CERT">TA08-079A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE" patch="1">APPLE-SA-2008-03-18</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41318" source="XF">macos-afpserver-security-bypass(41318)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN">ADV-2008-0924</ref>
      <ref url="http://www.securitytracker.com/id?1019642" source="SECTRACK">1019642</ref>
      <ref url="http://www.securityfocus.com/bid/28323" source="BID">28323</ref>
      <ref url="http://www.securityfocus.com/bid/28304" source="BID">28304</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA">29420</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0046" published="2008-03-18" name="CVE-2008-0046" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Application Firewall in Apple Mac OS X 10.5.2 has an incorrect German translation for the "Set access for specific services and applications" radio button that might cause the user to believe that the button is used to restrict access only to specific services and applications, which might allow attackers to bypass intended access restrictions.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" source="CERT">TA08-079A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE" patch="1">APPLE-SA-2008-03-18</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41317" source="XF">macos-applicationfirewall-weak-security(41317)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN">ADV-2008-0924</ref>
      <ref url="http://www.securitytracker.com/id?1019658" source="SECTRACK">1019658</ref>
      <ref url="http://www.securityfocus.com/bid/28368" source="BID">28368</ref>
      <ref url="http://www.securityfocus.com/bid/28304" source="BID">28304</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA">29420</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.2"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0047" published="2008-03-18" name="CVE-2008-0047" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the cgiCompileSearch function in CUPS 1.3.5, and other versions including the version bundled with Apple Mac OS X 10.5.2, when printer sharing is enabled, allows remote attackers to execute arbitrary code via crafted search expressions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" source="CERT">TA08-079A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE" patch="1">APPLE-SA-2008-03-18</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00105.html" source="FEDORA">FEDORA-2008-2897</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00091.html" source="FEDORA">FEDORA-2008-2131</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN" adv="1">ADV-2008-0924</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0921/references" source="VUPEN" adv="1">ADV-2008-0921</ref>
      <ref url="http://www.ubuntu.com/usn/usn-598-1" source="UBUNTU">USN-598-1</ref>
      <ref url="http://www.securitytracker.com/id?1019646" source="SECTRACK">1019646</ref>
      <ref url="http://www.securityfocus.com/bid/28307" source="BID">28307</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0192.html" source="REDHAT" adv="1">RHSA-2008:0192</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:081" source="MANDRIVA">MDVSA-2008:081</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1530" source="DEBIAN">DSA-1530</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200804-01.xml" source="GENTOO">GLSA-200804-01</ref>
      <ref url="http://secunia.com/advisories/29750" source="SECUNIA" adv="1">29750</ref>
      <ref url="http://secunia.com/advisories/29655" source="SECUNIA" adv="1">29655</ref>
      <ref url="http://secunia.com/advisories/29634" source="SECUNIA" adv="1">29634</ref>
      <ref url="http://secunia.com/advisories/29603" source="SECUNIA" adv="1">29603</ref>
      <ref url="http://secunia.com/advisories/29573" source="SECUNIA" adv="1">29573</ref>
      <ref url="http://secunia.com/advisories/29485" source="SECUNIA" adv="1">29485</ref>
      <ref url="http://secunia.com/advisories/29448" source="SECUNIA" adv="1">29448</ref>
      <ref url="http://secunia.com/advisories/29431" source="SECUNIA" adv="1">29431</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA" adv="1">29420</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10085" source="OVAL">oval:org.mitre.oval:def:10085</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00005.html" source="SUSE">SUSE-SA:2008:015</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=674" source="IDEFENSE">20080318 Multiple Vendor CUPS CGI Heap Overflow Vulnerability</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cups" name="cups">
        <vers num="1.3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0048" published="2008-03-18" name="CVE-2008-0048" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in AppKit in Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via the a long file name to the NSDocument API.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" source="CERT">TA08-079A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE" patch="1">APPLE-SA-2008-03-18</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41315" source="XF">macos-appkit-nsdocument-bo(41315)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN">ADV-2008-0924</ref>
      <ref url="http://www.securitytracker.com/id?1019647" source="SECTRACK">1019647</ref>
      <ref url="http://www.securityfocus.com/bid/28388" source="BID">28388</ref>
      <ref url="http://www.securityfocus.com/bid/28304" source="BID">28304</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA">29420</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2008-0049" published="2008-03-18" name="CVE-2008-0049" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">AppKit in Apple Mac OS X 10.4.11 inadvertently makes an NSApplication mach port available for inter-process communication instead of inter-thread communication, which allows local users to execute arbitrary code via crafted messages to privileged applications.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" source="CERT">TA08-079A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE" patch="1">APPLE-SA-2008-03-18</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41314" source="XF">macos-appkit-code-execution(41314)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN">ADV-2008-0924</ref>
      <ref url="http://www.securitytracker.com/id?1019647" source="SECTRACK">1019647</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
      <ref url="http://www.securityfocus.com/bid/28340" source="BID">28340</ref>
      <ref url="http://www.securityfocus.com/bid/28304" source="BID">28304</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA">29420</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0050" published="2008-03-18" name="CVE-2008-0050" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CFNetwork in Apple Mac OS X 10.4.11 allows remote HTTPS proxy servers to spoof secure websites via data in a 502 Bad Gateway error.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" source="CERT">TA08-079A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE" patch="1">APPLE-SA-2008-03-18</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41313" source="XF">macos-cfnetwork-502badgateway-spoofing(41313)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/2094/references" source="VUPEN">ADV-2008-2094</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN">ADV-2008-0924</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0920/references" source="VUPEN">ADV-2008-0920</ref>
      <ref url="http://www.securitytracker.com/id?1019655" source="SECTRACK">1019655</ref>
      <ref url="http://secunia.com/advisories/31074" source="SECUNIA">31074</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008//Jul/msg00001.html" source="APPLE">APPLE-SA-2008-07-11</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307563" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307563</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
      <ref url="http://www.securityfocus.com/bid/28356" source="BID">28356</ref>
      <ref url="http://www.securityfocus.com/bid/28290" source="BID">28290</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA">29420</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0051" published="2008-03-18" name="CVE-2008-0051" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Integer overflow in CoreFoundation in Apple Mac OS X 10.4.11 might allow local users to execute arbitrary code via crafted time zone data.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" source="CERT">TA08-079A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE" patch="1">APPLE-SA-2008-03-18</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41310" source="XF">macos-corefoundation-timezone-code-execution(41310)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN">ADV-2008-0924</ref>
      <ref url="http://www.securitytracker.com/id?1019670" source="SECTRACK">1019670</ref>
      <ref url="http://www.securityfocus.com/bid/28375" source="BID">28375</ref>
      <ref url="http://www.securityfocus.com/bid/28304" source="BID">28304</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA">29420</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0052" published="2008-03-18" name="CVE-2008-0052" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">CoreServices in Apple Mac OS X 10.4.11 treats .ief as a safe file type, which allows remote attackers to force Safari users into opening an .ief file in AppleWorks, even when the "Open 'Safe' files" preference is set.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" source="CERT">TA08-079A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE" patch="1">APPLE-SA-2008-03-18</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41312" source="XF">macos-coreservices-weak-security(41312)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN">ADV-2008-0924</ref>
      <ref url="http://www.securitytracker.com/id?1019671" source="SECTRACK">1019671</ref>
      <ref url="http://www.securityfocus.com/bid/28384" source="BID">28384</ref>
      <ref url="http://www.securityfocus.com/bid/28304" source="BID">28304</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA">29420</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0053" published="2008-03-18" name="CVE-2008-0053" modified="2011-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in the HP-GL/2-to-PostScript filter in CUPS before 1.3.6 might allow remote attackers to execute arbitrary code via a crafted HP-GL/2 file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" source="CERT">TA08-079A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE" patch="1">APPLE-SA-2008-03-18</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00105.html" source="FEDORA">FEDORA-2008-2897</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41272" source="XF">macos-cups-inputvalidation-unspecified(41272)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN" adv="1">ADV-2008-0924</ref>
      <ref url="http://www.ubuntu.com/usn/usn-598-1" source="UBUNTU">USN-598-1</ref>
      <ref url="http://www.securitytracker.com/id?1019672" source="SECTRACK">1019672</ref>
      <ref url="http://www.securityfocus.com/bid/28334" source="BID">28334</ref>
      <ref url="http://www.securityfocus.com/bid/28304" source="BID">28304</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0206.html" source="REDHAT">RHSA-2008:0206</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0192.html" source="REDHAT">RHSA-2008:0192</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:081" source="MANDRIVA">MDVSA-2008:081</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1625" source="DEBIAN">DSA-1625</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200804-01.xml" source="GENTOO">GLSA-200804-01</ref>
      <ref url="http://secunia.com/advisories/31324" source="SECUNIA" adv="1">31324</ref>
      <ref url="http://secunia.com/advisories/29750" source="SECUNIA" adv="1">29750</ref>
      <ref url="http://secunia.com/advisories/29659" source="SECUNIA" adv="1">29659</ref>
      <ref url="http://secunia.com/advisories/29655" source="SECUNIA" adv="1">29655</ref>
      <ref url="http://secunia.com/advisories/29634" source="SECUNIA" adv="1">29634</ref>
      <ref url="http://secunia.com/advisories/29630" source="SECUNIA" adv="1">29630</ref>
      <ref url="http://secunia.com/advisories/29603" source="SECUNIA" adv="1">29603</ref>
      <ref url="http://secunia.com/advisories/29573" source="SECUNIA" adv="1">29573</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA" adv="1">29420</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10356" source="OVAL">oval:org.mitre.oval:def:10356</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00003.html" source="SUSE">SUSE-SA:2008:020</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.10-1"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19" edition="rc1"/>
        <vers num="1.1.19" edition="rc2"/>
        <vers num="1.1.19" edition="rc3"/>
        <vers num="1.1.19" edition="rc4"/>
        <vers num="1.1.19" edition="rc5"/>
        <vers num="1.1.2"/>
        <vers num="1.1.20" edition="rc1"/>
        <vers num="1.1.20" edition="rc2"/>
        <vers num="1.1.20" edition="rc3"/>
        <vers num="1.1.20" edition="rc4"/>
        <vers num="1.1.20" edition="rc5"/>
        <vers num="1.1.20" edition="rc6"/>
        <vers num="1.1.21" edition="rc1"/>
        <vers num="1.1.21" edition="rc2"/>
        <vers num="1.1.22" edition="rc1"/>
        <vers num="1.1.22" edition="rc2"/>
        <vers num="1.1.23" edition="rc1"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.5-1"/>
        <vers num="1.1.5-2"/>
        <vers num="1.1.6"/>
        <vers num="1.1.6-1"/>
        <vers num="1.1.6-2"/>
        <vers num="1.1.6-3"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.1.9-1"/>
        <vers num="1.2" edition="b1"/>
        <vers num="1.2" edition="b2"/>
        <vers num="1.2" edition="rc1"/>
        <vers num="1.2" edition="rc2"/>
        <vers num="1.2" edition="rc3"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.10"/>
        <vers num="1.2.11"/>
        <vers num="1.2.12"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.2.8"/>
        <vers num="1.2.9"/>
        <vers num="1.3" edition="b1"/>
        <vers num="1.3" edition="rc1"/>
        <vers num="1.3" edition="rc2"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers prev="1" num="1.3.5"/>
        <vers num="1.3.9"/>
        <vers num="1.4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0054" published="2008-03-18" name="CVE-2008-0054" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Foundation in Apple Mac OS X 10.4.11 might allow context-dependent attackers to execute arbitrary code via a malformed selector name to the NSSelectorFromString API, which causes an "unexpected selector" to be used.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" source="CERT">TA08-079A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE" patch="1">APPLE-SA-2008-03-18</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41355" source="XF">macos-nsselectorfromstring-code-execution(41355)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN">ADV-2008-0924</ref>
      <ref url="http://www.securitytracker.com/id?1019649" source="SECTRACK">1019649</ref>
      <ref url="http://www.securityfocus.com/bid/28341" source="BID">28341</ref>
      <ref url="http://www.securityfocus.com/bid/28304" source="BID">28304</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA">29420</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0055" published="2008-03-18" name="CVE-2008-0055" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Foundation in Apple Mac OS X 10.4.11 creates world-writable directories while NSFileManager copies files recursively and only modifies the permissions afterward, which allows local users to modify copied files to cause a denial of service and possibly gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" source="CERT">TA08-079A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE" patch="1">APPLE-SA-2008-03-18</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41299" source="XF">macos-nsfilemanager-priv-escalation(41299)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN">ADV-2008-0924</ref>
      <ref url="http://www.securitytracker.com/id?1019649" source="SECTRACK">1019649</ref>
      <ref url="http://www.securityfocus.com/bid/28343" source="BID">28343</ref>
      <ref url="http://www.securityfocus.com/bid/28304" source="BID">28304</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA">29420</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0056" published="2008-03-18" name="CVE-2008-0056" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Foundation in Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a "long pathname with an unexpected structure" that triggers the overflow in NSFileManager.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" source="CERT">TA08-079A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE" patch="1">APPLE-SA-2008-03-18</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41309" source="XF">macos-foundation-nsfilemanager-bo(41309)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN">ADV-2008-0924</ref>
      <ref url="http://www.securitytracker.com/id?1019649" source="SECTRACK">1019649</ref>
      <ref url="http://www.securityfocus.com/bid/28357" source="BID">28357</ref>
      <ref url="http://www.securityfocus.com/bid/28304" source="BID">28304</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA">29420</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0057" published="2008-03-18" name="CVE-2008-0057" modified="2011-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in a "legacy serialization format" parser in AppKit in Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary code via a crafted serialized property list.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" source="CERT">TA08-079A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE" patch="1">APPLE-SA-2008-03-18</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41298" source="XF">macos-appkit-parser-bo(41298)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN" adv="1">ADV-2008-0924</ref>
      <ref url="http://www.securitytracker.com/id?1019648" source="SECTRACK">1019648</ref>
      <ref url="http://www.securityfocus.com/bid/28358" source="BID">28358</ref>
      <ref url="http://www.securityfocus.com/bid/28304" source="BID">28304</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0058" published="2008-03-18" name="CVE-2008-0058" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Race condition in the NSURLConnection cache management functionality in Foundation for Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary code via unspecified manipulations that cause messages to be sent to a deallocated object.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" source="CERT">TA08-079A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE" patch="1">APPLE-SA-2008-03-18</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41297" source="XF">macos-foundation-nsurl-code-execution(41297)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN">ADV-2008-0924</ref>
      <ref url="http://www.securitytracker.com/id?1019650" source="SECTRACK">1019650</ref>
      <ref url="http://www.securityfocus.com/bid/28359" source="BID">28359</ref>
      <ref url="http://www.securityfocus.com/bid/28304" source="BID">28304</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA">29420</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0059" published="2008-03-18" name="CVE-2008-0059" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Race condition in NSXML in Foundation for Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a crafted XML file, related to "error handling logic."</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" source="CERT">TA08-079A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE" patch="1">APPLE-SA-2008-03-18</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41296" source="XF">macos-foundation-code-execution(41296)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN">ADV-2008-0924</ref>
      <ref url="http://www.securitytracker.com/id?1019650" source="SECTRACK">1019650</ref>
      <ref url="http://www.securityfocus.com/bid/28367" source="BID">28367</ref>
      <ref url="http://www.securityfocus.com/bid/28304" source="BID">28304</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA">29420</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0060" published="2008-03-18" name="CVE-2008-0060" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Help Viewer in Apple Mac OS X 10.4.11 and 10.5.2 allows remote attackers to execute arbitrary Applescript via a help:topic_list URL that injects HTML or JavaScript into a topic list page, as demonstrated using a help:runscript link.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html" source="CERT">TA08-079A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE" patch="1">APPLE-SA-2008-03-18</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41295" source="XF">macos-helpviewer-code-execution(41295)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN">ADV-2008-0924</ref>
      <ref url="http://www.securitytracker.com/id?1019657" source="SECTRACK">1019657</ref>
      <ref url="http://www.securityfocus.com/bid/28371" source="BID">28371</ref>
      <ref url="http://www.securityfocus.com/bid/28304" source="BID">28304</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA">29420</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
        <vers num="10.5.2"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
        <vers num="10.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0061" published="2008-01-03" name="CVE-2008-0061" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MaraDNS 1.0 before 1.0.41, 1.2 before 1.2.12.08, and 1.3 before 1.3.07.04 allows remote attackers to cause a denial of service via a crafted DNS packet that prevents an authoritative name (CNAME) record from resolving, aka "improper rotation of resource records."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0026" source="VUPEN">ADV-2008-0026</ref>
      <ref url="http://www.maradns.org/changelog.html" source="CONFIRM">http://www.maradns.org/changelog.html</ref>
      <ref url="http://maradns.blogspot.com/2007/08/maradns-update-all-versions.html" source="CONFIRM">http://maradns.blogspot.com/2007/08/maradns-update-all-versions.html</ref>
      <ref url="http://www.securityfocus.com/bid/27124" source="BID">27124</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1445" source="DEBIAN">DSA-1445</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200801-16.xml" source="GENTOO">GLSA-200801-16</ref>
      <ref url="http://secunia.com/advisories/28650" source="SECUNIA">28650</ref>
      <ref url="http://secunia.com/advisories/28334" source="SECUNIA">28334</ref>
      <ref url="http://secunia.com/advisories/28329" source="SECUNIA">28329</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=204351" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=204351</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maradns" name="maradns">
        <vers num="1.0.00"/>
        <vers num="1.0.01"/>
        <vers num="1.0.02"/>
        <vers num="1.0.03"/>
        <vers num="1.0.04"/>
        <vers num="1.0.05"/>
        <vers num="1.0.06"/>
        <vers num="1.0.07"/>
        <vers num="1.0.08"/>
        <vers num="1.0.09"/>
        <vers num="1.0.10"/>
        <vers num="1.0.11"/>
        <vers num="1.0.12"/>
        <vers num="1.0.13"/>
        <vers num="1.0.14"/>
        <vers num="1.0.15"/>
        <vers num="1.0.16"/>
        <vers num="1.0.17"/>
        <vers num="1.0.18"/>
        <vers num="1.0.19"/>
        <vers num="1.0.20"/>
        <vers num="1.0.21"/>
        <vers num="1.0.22"/>
        <vers num="1.0.23"/>
        <vers num="1.0.24"/>
        <vers num="1.0.25"/>
        <vers num="1.0.26"/>
        <vers num="1.0.27"/>
        <vers num="1.0.28"/>
        <vers num="1.0.29"/>
        <vers num="1.0.30"/>
        <vers num="1.0.31"/>
        <vers num="1.0.32"/>
        <vers num="1.0.33"/>
        <vers num="1.0.34"/>
        <vers num="1.0.35"/>
        <vers num="1.0.36"/>
        <vers num="1.0.37"/>
        <vers num="1.0.38"/>
        <vers num="1.0.39"/>
        <vers num="1.2.12.01"/>
        <vers num="1.2.12.02"/>
        <vers num="1.2.12.03"/>
        <vers num="1.2.12.04"/>
        <vers num="1.2.12.05"/>
        <vers num="1.2.12.06"/>
        <vers num="1.2.12.07"/>
        <vers num="1.3.01"/>
        <vers num="1.3.02"/>
        <vers num="1.3.03"/>
        <vers num="1.3.04"/>
        <vers num="1.3.05"/>
        <vers num="1.3.06"/>
        <vers num="1.3.07"/>
        <vers num="1.3.07.01"/>
        <vers num="1.3.07.02"/>
        <vers num="1.3.07.03"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0062" published="2008-03-19" name="CVE-2008-0062" modified="2011-09-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/895609" source="CERT-VN">VU#895609</ref>
      <ref url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2008-001.txt" source="CONFIRM" patch="1">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2008-001.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41275" source="XF">krb5-kdc-code-execution(41275)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1744" source="VUPEN">ADV-2008-1744</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1102/references" source="VUPEN">ADV-2008-1102</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN">ADV-2008-0924</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0922/references" source="VUPEN">ADV-2008-0922</ref>
      <ref url="http://www.securityfocus.com/archive/1/489761" source="BUGTRAQ">20080318 MITKRB5-SA-2008-001: double-free, uninitialized data vulnerabilities in krb5kdc</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9496" source="OVAL">oval:org.mitre.oval:def:9496</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=130497213107107&amp;w=2" source="HP">SSRT100495</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=130497213107107&amp;w=2" source="HP">HPSBOV02682</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE">APPLE-SA-2008-03-18</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00544.html" source="FEDORA">FEDORA-2008-2647</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00537.html" source="FEDORA">FEDORA-2008-2637</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2008-0009.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2008-0009.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-587-1" source="UBUNTU">USN-587-1</ref>
      <ref url="http://www.securitytracker.com/id?1019626" source="SECTRACK">1019626</ref>
      <ref url="http://www.securityfocus.com/bid/28303" source="BID">28303</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/493080/100/0/threaded" source="BUGTRAQ">20080604 VMSA-2008-0009 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/489883/100/0/threaded" source="BUGTRAQ">20080319 rPSA-2008-0112-1 krb5 krb5-server krb5-services krb5-test krb5-workstation</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0182.html" source="REDHAT">RHSA-2008:0182</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0181.html" source="REDHAT">RHSA-2008:0181</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0180.html" source="REDHAT">RHSA-2008:0180</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0164.html" source="REDHAT">RHSA-2008:0164</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:071" source="MANDRIVA">MDVSA-2008:071</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:070" source="MANDRIVA">MDVSA-2008:070</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:069" source="MANDRIVA">MDVSA-2008:069</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200803-31.xml" source="GENTOO">GLSA-200803-31</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1524" source="DEBIAN">DSA-1524</ref>
      <ref url="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0112" source="CONFIRM">http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0112</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2008-0112" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2008-0112</ref>
      <ref url="http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022542.html" source="CONFIRM">http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022542.html</ref>
      <ref url="http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022520.html" source="CONFIRM">http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022520.html</ref>
      <ref url="http://secunia.com/advisories/30535" source="SECUNIA">30535</ref>
      <ref url="http://secunia.com/advisories/29663" source="SECUNIA">29663</ref>
      <ref url="http://secunia.com/advisories/29516" source="SECUNIA">29516</ref>
      <ref url="http://secunia.com/advisories/29464" source="SECUNIA">29464</ref>
      <ref url="http://secunia.com/advisories/29462" source="SECUNIA">29462</ref>
      <ref url="http://secunia.com/advisories/29457" source="SECUNIA">29457</ref>
      <ref url="http://secunia.com/advisories/29451" source="SECUNIA">29451</ref>
      <ref url="http://secunia.com/advisories/29450" source="SECUNIA">29450</ref>
      <ref url="http://secunia.com/advisories/29438" source="SECUNIA">29438</ref>
      <ref url="http://secunia.com/advisories/29435" source="SECUNIA">29435</ref>
      <ref url="http://secunia.com/advisories/29428" source="SECUNIA">29428</ref>
      <ref url="http://secunia.com/advisories/29424" source="SECUNIA">29424</ref>
      <ref url="http://secunia.com/advisories/29423" source="SECUNIA">29423</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA">29420</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00006.html" source="SUSE">SUSE-SA:2008:016</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos_5">
        <vers prev="1" num="1.6.3_kdc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0063" published="2008-03-19" name="CVE-2008-0063" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2008-001.txt" source="CONFIRM" patch="1">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2008-001.txt</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00544.html" source="FEDORA">FEDORA-2008-2647</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00537.html" source="FEDORA">FEDORA-2008-2637</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41277" source="XF">krb5-kdc-kerberos4-info-disclosure(41277)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1744" source="VUPEN" adv="1">ADV-2008-1744</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1102/references" source="VUPEN" adv="1">ADV-2008-1102</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN" adv="1">ADV-2008-0924</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0922/references" source="VUPEN" adv="1">ADV-2008-0922</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2008-0009.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2008-0009.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-587-1" source="UBUNTU">USN-587-1</ref>
      <ref url="http://www.securitytracker.com/id?1019627" source="SECTRACK">1019627</ref>
      <ref url="http://www.securityfocus.com/bid/28303" source="BID">28303</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/493080/100/0/threaded" source="BUGTRAQ">20080604 VMSA-2008-0009 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/489883/100/0/threaded" source="BUGTRAQ">20080319 rPSA-2008-0112-1 krb5 krb5-server krb5-services krb5-test krb5-workstation</ref>
      <ref url="http://www.securityfocus.com/archive/1/489761" source="BUGTRAQ">20080318 MITKRB5-SA-2008-001: double-free, uninitialized data vulnerabilities in krb5kdc</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0182.html" source="REDHAT">RHSA-2008:0182</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0181.html" source="REDHAT">RHSA-2008:0181</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0180.html" source="REDHAT">RHSA-2008:0180</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0164.html" source="REDHAT">RHSA-2008:0164</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:071" source="MANDRIVA">MDVSA-2008:071</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:070" source="MANDRIVA">MDVSA-2008:070</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:069" source="MANDRIVA">MDVSA-2008:069</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200803-31.xml" source="GENTOO">GLSA-200803-31</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1524" source="DEBIAN">DSA-1524</ref>
      <ref url="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0112" source="CONFIRM">http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0112</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2008-0112" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2008-0112</ref>
      <ref url="http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022542.html" source="CONFIRM">http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022542.html</ref>
      <ref url="http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022520.html" source="CONFIRM">http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022520.html</ref>
      <ref url="http://secunia.com/advisories/30535" source="SECUNIA" adv="1">30535</ref>
      <ref url="http://secunia.com/advisories/29663" source="SECUNIA" adv="1">29663</ref>
      <ref url="http://secunia.com/advisories/29516" source="SECUNIA" adv="1">29516</ref>
      <ref url="http://secunia.com/advisories/29464" source="SECUNIA" adv="1">29464</ref>
      <ref url="http://secunia.com/advisories/29462" source="SECUNIA" adv="1">29462</ref>
      <ref url="http://secunia.com/advisories/29457" source="SECUNIA" adv="1">29457</ref>
      <ref url="http://secunia.com/advisories/29451" source="SECUNIA" adv="1">29451</ref>
      <ref url="http://secunia.com/advisories/29450" source="SECUNIA" adv="1">29450</ref>
      <ref url="http://secunia.com/advisories/29438" source="SECUNIA" adv="1">29438</ref>
      <ref url="http://secunia.com/advisories/29435" source="SECUNIA" adv="1">29435</ref>
      <ref url="http://secunia.com/advisories/29428" source="SECUNIA" adv="1">29428</ref>
      <ref url="http://secunia.com/advisories/29424" source="SECUNIA" adv="1">29424</ref>
      <ref url="http://secunia.com/advisories/29423" source="SECUNIA" adv="1">29423</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA" adv="1">29420</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8916" source="OVAL">oval:org.mitre.oval:def:8916</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00006.html" source="SUSE">SUSE-SA:2008:016</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE">APPLE-SA-2008-03-18</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos_5">
        <vers prev="1" num="1.6.3_kdc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0064" published="2008-01-31" name="CVE-2008-0064" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Pierre-emmanuel Gougelet (1) XnView 1.91 and 1.92, (2) NConvert 4.85, and (3) libgfl280.dll in GFL SDK 2.870 for Windows allows user-assisted remote attackers to execute arbitrary code via a crafted Radiance RGBE (.hdr) file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/28326" source="SECUNIA" patch="1" adv="1">28326</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0329" source="VUPEN">ADV-2008-0329</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0328" source="VUPEN">ADV-2008-0328</ref>
      <ref url="http://www.securityfocus.com/bid/27514" source="BID">27514</ref>
      <ref url="http://secunia.com/secunia_research/2008-1/advisory" source="MISC" adv="1">http://secunia.com/secunia_research/2008-1/advisory</ref>
      <ref url="http://secunia.com/advisories/28710" source="SECUNIA" adv="1">28710</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pierreegougelet" name="gfl_sdk">
        <vers num="2.870" edition=""/>
        <vers num="2.870" edition=":windows"/>
      </prod>
      <prod vendor="pierreegougelet" name="nconvert">
        <vers prev="1" num="4.85"/>
      </prod>
      <prod vendor="pierreegougelet" name="xnview">
        <vers prev="1" num="1.91"/>
        <vers prev="1" num="1.92"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0065" published="2008-01-22" name="CVE-2008-0065" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in in_mp3.dll in Winamp 5.21, 5.5, and 5.51 allow remote attackers to execute arbitrary code via a long (1) artist or (2) name tag in Ultravox streaming metadata, related to construction of stream titles.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.winamp.com/player/version-history" source="CONFIRM">http://www.winamp.com/player/version-history</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0183" source="VUPEN">ADV-2008-0183</ref>
      <ref url="http://secunia.com/secunia_research/2008-2/advisory/" source="MISC">http://secunia.com/secunia_research/2008-2/advisory/</ref>
      <ref url="http://secunia.com/advisories/27865" source="SECUNIA" adv="1">27865</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39778" source="XF">winamp-inmp3-bo(39778)</ref>
      <ref url="http://www.securityfocus.com/bid/27344" source="BID">27344</ref>
    </refs>
    <vuln_soft>
      <prod vendor="winamp" name="nullsoft_winamp">
        <vers num="5.21"/>
        <vers num="5.5"/>
        <vers num="5.51"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0066" published="2008-04-10" name="CVE-2008-0066" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple buffer overflows in htmsr.dll in the HTML speed reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes 7.0.2 and 7.0.3, allow remote attackers to execute arbitrary code via an HTML document with (1) "large chunks of data," or a long URL in the (2) BACKGROUND attribute of a BODY element or (3) SRC attribute of an IMG element.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/41724" source="XF">autonomy-keyview-html-multiple-bo(41724)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1156" source="VUPEN">ADV-2008-1156</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1153" source="VUPEN">ADV-2008-1153</ref>
      <ref url="http://www.securitytracker.com/id?1019843" source="SECTRACK">1019843</ref>
      <ref url="http://www.securityfocus.com/bid/28454" source="BID">28454</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/490828/100/0/threaded" source="BUGTRAQ">20080414 Secunia Research: Lotus Notes htmsr.dll Buffer Overflows</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21298453" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21298453</ref>
      <ref url="http://secunia.com/secunia_research/2008-3/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2008-3/advisory/</ref>
      <ref url="http://secunia.com/advisories/28210" source="SECUNIA" adv="1">28210</ref>
      <ref url="http://secunia.com/advisories/28209" source="SECUNIA" adv="1">28209</ref>
      <ref url="http://secunia.com/advisories/28140" source="SECUNIA" adv="1">28140</ref>
    </refs>
    <vuln_soft>
      <prod vendor="autonomy" name="keyview">
        <vers num=""/>
      </prod>
      <prod vendor="ibm" name="lotus_notes">
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0067" published="2009-01-08" name="CVE-2008-0067" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via (1) long string parameters to the OpenView5.exe CGI program; (2) a long string parameter to the OpenView5.exe CGI program, related to ov.dll; or a long string parameter to the (3) getcvdata.exe, (4) ovlaunch.exe, or (5) Toolbar.exe CGI program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33147" source="BID">33147</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/499826/100/0/threaded" source="BUGTRAQ">20090107 Secunia Research: HP OpenView Network Node Manager Multiple Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1021521" source="SECTRACK">1021521</ref>
      <ref url="http://securityreason.com/securityalert/8307" source="SREASON">8307</ref>
      <ref url="http://securityreason.com/securityalert/4885" source="SREASON">4885</ref>
      <ref url="http://secunia.com/secunia_research/2008-13/" source="MISC" adv="1">http://secunia.com/secunia_research/2008-13/</ref>
      <ref url="http://secunia.com/advisories/28074" source="SECUNIA" adv="1">28074</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=123247393715913&amp;w=2" source="HP">SSRT080144</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=123247393715913&amp;w=2" source="HP">SSRT080144</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="7.51"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0068" published="2008-04-16" name="CVE-2008-0068" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in OpenView5.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to read arbitrary files via directory traversal sequences in the Action parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/41790" source="XF">hpopenview-openview5-directory-traversal(41790)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1214/references" source="VUPEN">ADV-2008-1214</ref>
      <ref url="http://www.securityfocus.com/bid/28745" source="BID">28745</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/490834/100/0/threaded" source="BUGTRAQ">20080414 Secunia Research: HP OpenView Network Node Manager OpenView5.exeDirectory Traversal</ref>
      <ref url="http://www.securityfocus.com/archive/1/490771" source="BUGTRAQ">20080411 Directory traversal and multiple Denials of Service in HP OpenView NNM 7.53</ref>
      <ref url="http://securityreason.com/securityalert/3814" source="SREASON">3814</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=121553649611253&amp;w=2" source="HP">HPSBMA02349</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=121553649611253&amp;w=2" source="HP">HPSBMA02349</ref>
      <ref url="http://aluigi.altervista.org/adv/closedviewx-adv.txt" source="MISC">http://aluigi.altervista.org/adv/closedviewx-adv.txt</ref>
      <ref url="http://www.securitytracker.com/id?1019839" source="SECTRACK">1019839</ref>
      <ref url="http://www.securitytracker.com/id?1019838" source="SECTRACK">1019838</ref>
      <ref url="http://www.osvdb.org/44359" source="OSVDB">44359</ref>
      <ref url="http://secunia.com/secunia_research/2008-4/advisory/" source="MISC">http://secunia.com/secunia_research/2008-4/advisory/</ref>
      <ref url="http://secunia.com/advisories/29796" source="SECUNIA">29796</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="7.51"/>
        <vers num="7.53"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0069" published="2008-04-02" name="CVE-2008-0069" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in XnView 1.92 and 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long FontName parameter in a slideshow (.sld) file, a different vector than CVE-2008-1461.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/29620" source="SECUNIA" patch="1" adv="1">29620</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41542" source="XF">xnview-slideshow-bo(41542)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1044/references" source="VUPEN">ADV-2008-1044</ref>
      <ref url="http://www.securityfocus.com/bid/28579" source="BID">28579</ref>
      <ref url="http://www.milw0rm.com/exploits/5346" source="MILW0RM">5346</ref>
      <ref url="http://secunia.com/secunia_research/2008-6/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2008-6/advisory/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pierreegougelet" name="xnview">
        <vers prev="1" num="1.92"/>
        <vers prev="1" num="1.92.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0070" published="2008-03-31" name="CVE-2008-0070" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Integer overflow in Orb Networks Orb 2.00.1014 and Winamp Remote BETA allows remote attackers to execute arbitrary code via an RPC request that specifies a large number of array dimensions, which triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/41410" source="XF" patch="1">orb-dimensions-bo(41410)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0984/references" source="VUPEN">ADV-2008-0984</ref>
      <ref url="http://www.securityfocus.com/bid/28431" source="BID">28431</ref>
      <ref url="http://secunia.com/secunia_research/2008-5/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2008-5/advisory/</ref>
      <ref url="http://secunia.com/advisories/28203" source="SECUNIA" adv="1">28203</ref>
    </refs>
    <vuln_soft>
      <prod vendor="orb_networks" name="orb">
        <vers num="2.0.1014"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0071" published="2008-06-16" name="CVE-2008-0071" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The Web UI interface in (1) BitTorrent before 6.0.3 build 8642 and (2) uTorrent before 1.8beta build 10524 allows remote attackers to cause a denial of service (application crash) via an HTTP request with a malformed Range header.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/29661" source="BID" patch="1">29661</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1809" source="VUPEN">ADV-2008-1809</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1808" source="VUPEN">ADV-2008-1808</ref>
      <ref url="http://www.securitytracker.com/id?1020265" source="SECTRACK">1020265</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/493269/100/0/threaded" source="BUGTRAQ">20080611 Secunia Research: uTorrent / BitTorrent Web UI HTTP "Range" Header DoS</ref>
      <ref url="http://www.milw0rm.com/exploits/5918" source="MILW0RM">5918</ref>
      <ref url="http://securitytracker.com/id?1020266" source="SECTRACK">1020266</ref>
      <ref url="http://securityreason.com/securityalert/3943" source="SREASON">3943</ref>
      <ref url="http://secunia.com/secunia_research/2008-7/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2008-7/advisory/</ref>
      <ref url="http://secunia.com/advisories/30605" source="SECUNIA" adv="1">30605</ref>
      <ref url="http://secunia.com/advisories/28703" source="SECUNIA" adv="1">28703</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bittorrent" name="bittorrent">
        <vers num="3.9.1"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1.0"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.1.6"/>
        <vers num="4.1.7"/>
        <vers num="4.1.8"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.20.0"/>
        <vers num="4.20.1"/>
        <vers num="4.20.2"/>
        <vers num="4.20.4"/>
        <vers num="4.20.6"/>
        <vers num="4.20.7"/>
        <vers num="4.20.8"/>
        <vers num="4.20.9"/>
        <vers num="4.22.0"/>
        <vers num="4.22.1"/>
        <vers num="4.22.4"/>
        <vers num="4.24.0"/>
        <vers num="4.24.2"/>
        <vers num="4.26.0"/>
        <vers num="4.27.1"/>
        <vers num="4.27.2"/>
        <vers num="4.3.0"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
        <vers num="4.3.4"/>
        <vers num="4.3.5"/>
        <vers num="4.3.6"/>
        <vers num="4.4.0"/>
        <vers num="4.4.1"/>
        <vers num="4.9.2"/>
        <vers num="4.9.3"/>
        <vers num="4.9.4"/>
        <vers num="4.9.5"/>
        <vers num="4.9.6"/>
        <vers num="4.9.7"/>
        <vers num="4.9.8"/>
        <vers num="4.9.9"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
        <vers num="5.0.8"/>
        <vers num="5.0.9"/>
        <vers num="5.2.0"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers prev="1" num="6.0.2"/>
      </prod>
      <prod vendor="utorrent" name="utorrent">
        <vers num="1.1.1"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.3"/>
        <vers num="1.4"/>
        <vers num="1.4.2"/>
        <vers num="1.5"/>
        <vers num="1.6"/>
        <vers num="1.7"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="1.7.3"/>
        <vers num="1.7.4"/>
        <vers num="1.7.5"/>
        <vers num="1.7.6"/>
        <vers prev="1" num="1.7.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0072" published="2008-03-05" name="CVE-2008-0072" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Format string vulnerability in the emf_multipart_encrypted function in mail/em-format.c in Evolution 2.12.3 and earlier allows remote attackers to execute arbitrary code via a crafted encrypted message, as demonstrated using the Version field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/512491" source="CERT-VN">VU#512491</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1512" source="DEBIAN" patch="1">DSA-1512</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00195.html" source="FEDORA">FEDORA-2008-2292</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00190.html" source="FEDORA">FEDORA-2008-2290</ref>
      <ref url="https://issues.rpath.com/browse/RPL-2310" source="CONFIRM">https://issues.rpath.com/browse/RPL-2310</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41011" source="XF" adv="1">evolution-emfmultipart-format-string(41011)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0768/references" source="VUPEN" adv="1">ADV-2008-0768</ref>
      <ref url="http://www.ubuntu.com/usn/usn-583-1" source="UBUNTU">USN-583-1</ref>
      <ref url="http://www.securitytracker.com/id?1019540" source="SECTRACK">1019540</ref>
      <ref url="http://www.securityfocus.com/bid/28102" source="BID">28102</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/492684/100/0/threaded" source="BUGTRAQ">20080528 rPSA-2008-0105-1 evolution</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0178.html" source="REDHAT" adv="1">RHSA-2008:0178</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0177.html" source="REDHAT" adv="1">RHSA-2008:0177</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:063" source="MANDRIVA">MDVSA-2008:063</ref>
      <ref url="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0105" source="CONFIRM">http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0105</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200803-12.xml" source="GENTOO">GLSA-200803-12</ref>
      <ref url="http://secunia.com/secunia_research/2008-8/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2008-8/advisory/</ref>
      <ref url="http://secunia.com/advisories/30491" source="SECUNIA" adv="1">30491</ref>
      <ref url="http://secunia.com/advisories/30437" source="SECUNIA" adv="1">30437</ref>
      <ref url="http://secunia.com/advisories/29317" source="SECUNIA" adv="1">29317</ref>
      <ref url="http://secunia.com/advisories/29264" source="SECUNIA" adv="1">29264</ref>
      <ref url="http://secunia.com/advisories/29258" source="SECUNIA" adv="1">29258</ref>
      <ref url="http://secunia.com/advisories/29244" source="SECUNIA" adv="1">29244</ref>
      <ref url="http://secunia.com/advisories/29210" source="SECUNIA" adv="1">29210</ref>
      <ref url="http://secunia.com/advisories/29163" source="SECUNIA" adv="1">29163</ref>
      <ref url="http://secunia.com/advisories/29057" source="SECUNIA" adv="1">29057</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10701" source="OVAL">oval:org.mitre.oval:def:10701</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00003.html" source="SUSE">SUSE-SA:2008:014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="evolution">
        <vers prev="1" num="2.12.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0073" published="2008-03-24" name="CVE-2008-0073" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP servers to execute arbitrary code via a large streamid SDP parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xinehq.de/index.php/news" source="CONFIRM" patch="1">http://xinehq.de/index.php/news</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=585488&amp;group_id=9655" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=585488&amp;group_id=9655</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41339" source="XF">xinelib-sdpplinparse-bo(41339)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0985" source="VUPEN">ADV-2008-0985</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0923" source="VUPEN">ADV-2008-0923</ref>
      <ref url="http://www.ubuntu.com/usn/usn-635-1" source="UBUNTU">USN-635-1</ref>
      <ref url="http://www.securityfocus.com/bid/28312" source="BID">28312</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:219" source="MANDRIVA">MDVSA-2008:219</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:178" source="MANDRIVA">MDVSA-2008:178</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200808-01.xml" source="GENTOO">GLSA-200808-01</ref>
      <ref url="http://secunia.com/secunia_research/2008-10/" source="MISC" adv="1">http://secunia.com/secunia_research/2008-10/</ref>
      <ref url="http://secunia.com/advisories/31393" source="SECUNIA">31393</ref>
      <ref url="http://secunia.com/advisories/31372" source="SECUNIA">31372</ref>
      <ref url="http://secunia.com/advisories/30581" source="SECUNIA">30581</ref>
      <ref url="http://secunia.com/advisories/29503" source="SECUNIA">29503</ref>
      <ref url="http://secunia.com/advisories/28694" source="SECUNIA" adv="1">28694</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00456.html" source="FEDORA">FEDORA-2008-2569</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00143.html" source="FEDORA">FEDORA-2008-2945</ref>
      <ref url="http://www.videolan.org/security/sa0803.php" source="CONFIRM">http://www.videolan.org/security/sa0803.php</ref>
      <ref url="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2008&amp;m=slackware-security.392408" source="SLACKWARE">SSA:2008-089-03</ref>
      <ref url="http://www.securitytracker.com/id?1019682" source="SECTRACK">1019682</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1543" source="DEBIAN">DSA-1543</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1536" source="DEBIAN">DSA-1536</ref>
      <ref url="http://wiki.videolan.org/Changelog/0.8.6f" source="CONFIRM">http://wiki.videolan.org/Changelog/0.8.6f</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200804-25.xml" source="GENTOO">GLSA-200804-25</ref>
      <ref url="http://secunia.com/advisories/29800" source="SECUNIA">29800</ref>
      <ref url="http://secunia.com/advisories/29766" source="SECUNIA">29766</ref>
      <ref url="http://secunia.com/advisories/29740" source="SECUNIA">29740</ref>
      <ref url="http://secunia.com/advisories/29601" source="SECUNIA">29601</ref>
      <ref url="http://secunia.com/advisories/29578" source="SECUNIA">29578</ref>
      <ref url="http://secunia.com/advisories/29472" source="SECUNIA">29472</ref>
      <ref url="http://secunia.com/advisories/29392" source="SECUNIA">29392</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00001.html" source="SUSE">SUSE-SR:2008:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00008.html" source="SUSE">SUSE-SR:2008:007</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xine" name="xine-lib">
        <vers num="1.1.10.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0074" published="2008-02-12" name="CVE-2008-0074" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows local users to gain privileges via unknown vectors related to file change notifications in the TPRoot, NNTPFile\Root, or WWWRoot folders.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" source="CERT">TA08-043C</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0507/references" source="VUPEN">ADV-2008-0507</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">SSRT080016</ref>
      <ref url="http://www.securitytracker.com/id?1019384" source="SECTRACK">1019384</ref>
      <ref url="http://www.securityfocus.com/bid/27101" source="BID">27101</ref>
      <ref url="http://secunia.com/advisories/28849" source="SECUNIA">28849</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">HPSBST02314</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5389" source="OVAL" sig="1">oval:org.mitre.oval:def:5389</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="iis">
        <vers num="7.0"/>
      </prod>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="6.0" edition="beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0075" published="2008-02-12" name="CVE-2008-0075" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 through 6.0 allows remote attackers to execute arbitrary code via crafted inputs to ASP pages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" source="CERT">TA08-043C</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0508/references" source="VUPEN">ADV-2008-0508</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">SSRT080016</ref>
      <ref url="http://www.securitytracker.com/id?1019385" source="SECTRACK">1019385</ref>
      <ref url="http://www.securityfocus.com/bid/27676" source="BID">27676</ref>
      <ref url="http://secunia.com/advisories/28893" source="SECUNIA">28893</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">HPSBST02314</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5308" source="OVAL" sig="1">oval:org.mitre.oval:def:5308</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="5.1"/>
        <vers num="6.0" edition="beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0076" published="2008-02-12" name="CVE-2008-0076" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via crafted HTML layout combinations, aka "HTML Rendering Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" source="CERT">TA08-043C</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0512/references" source="VUPEN">ADV-2008-0512</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-010.mspx" source="MS">MS08-010</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">SSRT080016</ref>
      <ref url="http://www.securitytracker.com/id?1019379" source="SECTRACK">1019379</ref>
      <ref url="http://www.securityfocus.com/bid/27668" source="BID">27668</ref>
      <ref url="http://secunia.com/advisories/28903" source="SECUNIA">28903</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">HPSBST02314</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5487" source="OVAL" sig="1">oval:org.mitre.oval:def:5487</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="windows_2000_sp4"/>
        <vers num="6" edition="windows_server_2003_sp1"/>
        <vers num="6" edition="windows_server_2003_sp1_itanium"/>
        <vers num="6" edition="windows_xp_sp2"/>
        <vers num="7" edition="windows_server_2003_sp1"/>
        <vers num="7" edition="windows_xp_sp2"/>
      </prod>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="6" edition=""/>
        <vers num="6" edition=":windows_xp_professional_x64_edition_sp2"/>
        <vers num="6" edition=":windows_server_2003_x64_edition_sp2"/>
        <vers num="6" edition=":windows_server_2003_sp2"/>
        <vers num="6" edition=":windows_server_2003_x64_edition"/>
        <vers num="6" edition=":windows_xp_professional_x64_edition"/>
        <vers num="6" edition=":windows_server_2003_sp2_itanium"/>
        <vers num="7" edition=""/>
        <vers num="7" edition=":windows_server_2003_x64_edition"/>
        <vers num="7" edition=":windows_server_2003_x64_edition_sp2"/>
        <vers num="7" edition=":windows_server_2003_sp1_itanium"/>
        <vers num="7" edition=":windows_xp_professional_x64_edition"/>
        <vers num="7" edition=":windows_vista_x64"/>
        <vers num="7" edition=":windows_server_2003_sp2"/>
        <vers num="7" edition=":windows_xp_professional_x64_edition_sp2"/>
        <vers num="7" edition=":windows_vista"/>
        <vers num="7" edition=":windows_server_2003_sp2_itanium"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0077" published="2008-02-12" name="CVE-2008-0077" modified="2011-04-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 6 SP1, 6 SP2, and and 7 allows remote attackers to execute arbitrary code by assigning malformed values to certain properties, as demonstrated using the by property of an animateMotion SVG element, aka "Property Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" source="CERT">TA08-043C</ref>
      <ref url="http://www.kb.cert.org/vuls/id/228569" source="CERT-VN">VU#228569</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-010.mspx" source="MS" patch="1" adv="1">MS08-010</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-08-006.html" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-08-006.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0512/references" source="VUPEN" adv="1">ADV-2008-0512</ref>
      <ref url="http://www.securitytracker.com/id?1019380" source="SECTRACK">1019380</ref>
      <ref url="http://www.securityfocus.com/bid/27666" source="BID">27666</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488048/100/0/threaded" source="BUGTRAQ">20080213 ZDI-08-006: Microsoft Internet Explorer SVG animateMotion.by Code Execution Vulnerability</ref>
      <ref url="http://secunia.com/advisories/28903" source="SECUNIA" adv="1">28903</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">SSRT080016</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">SSRT080016</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=661" source="IDEFENSE">20080212 Microsoft Internet Explorer Property Memory Corruption Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5396" source="OVAL" sig="1">oval:org.mitre.oval:def:5396</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6" edition="sp1"/>
        <vers num="7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0078" published="2008-02-12" name="CVE-2008-0078" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in an ActiveX control (dxtmsft.dll) in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via a crafted image, aka "Argument Handling Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" source="CERT">TA08-043C</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0512/references" source="VUPEN">ADV-2008-0512</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-010.mspx" source="MS">MS08-010</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">SSRT080016</ref>
      <ref url="http://www.securitytracker.com/id?1019381" source="SECTRACK">1019381</ref>
      <ref url="http://www.securityfocus.com/bid/27689" source="BID">27689</ref>
      <ref url="http://secunia.com/advisories/28903" source="SECUNIA">28903</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">HPSBST02314</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4904" source="OVAL" sig="1">oval:org.mitre.oval:def:4904</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="activex">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="windows_2000_sp4"/>
        <vers num="6" edition="windows_server_2003_sp1"/>
        <vers num="6" edition="windows_server_2003_sp1_itanium"/>
        <vers num="6" edition="windows_xp_sp2"/>
        <vers num="7" edition="windows_server_2003_sp1"/>
        <vers num="7" edition="windows_xp_sp2"/>
      </prod>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="6" edition=""/>
        <vers num="6" edition=":windows_xp_professional_x64_edition_sp2"/>
        <vers num="6" edition=":windows_server_2003_x64_edition_sp2"/>
        <vers num="6" edition=":windows_server_2003_sp2"/>
        <vers num="6" edition=":windows_server_2003_x64_edition"/>
        <vers num="6" edition=":windows_xp_professional_x64_edition"/>
        <vers num="6" edition=":windows_server_2003_sp2_itanium"/>
        <vers num="7" edition=""/>
        <vers num="7" edition=":windows_server_2003_x64_edition"/>
        <vers num="7" edition=":windows_server_2003_x64_edition_sp2"/>
        <vers num="7" edition=":windows_server_2003_sp1_itanium"/>
        <vers num="7" edition=":windows_xp_professional_x64_edition"/>
        <vers num="7" edition=":windows_vista_x64"/>
        <vers num="7" edition=":windows_server_2003_sp2"/>
        <vers num="7" edition=":windows_xp_professional_x64_edition_sp2"/>
        <vers num="7" edition=":windows_vista"/>
        <vers num="7" edition=":windows_server_2003_sp2_itanium"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0080" published="2008-02-12" name="CVE-2008-0080" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the WebDAV Mini-Redirector in Microsoft Windows XP SP2, Server 2003 SP1 and SP2, and Vista allows remote attackers to execute arbitrary code via a crafted WebDAV response.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" source="CERT">TA08-043C</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0509/references" source="VUPEN">ADV-2008-0509</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-007.mspx" source="MS">MS08-007</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">SSRT080016</ref>
      <ref url="http://www.securitytracker.com/id?1019372" source="SECTRACK">1019372</ref>
      <ref url="http://www.securityfocus.com/bid/27670" source="BID">27670</ref>
      <ref url="http://secunia.com/advisories/28894" source="SECUNIA">28894</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">HPSBST02314</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5381" source="OVAL" sig="1">oval:org.mitre.oval:def:5381</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="webdav_mini-redirector">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0081" published="2008-01-16" name="CVE-2008-0081" modified="2011-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted macros, aka "Macro Validation Vulnerability," a different vulnerability than CVE-2007-3490.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-071A.html" source="CERT">TA08-071A</ref>
      <ref url="http://www.securityfocus.com/bid/27305" source="BID" patch="1">27305</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-014.mspx" source="MS" patch="1">MS08-014</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/947563.mspx" source="CONFIRM" patch="1" adv="1">http://www.microsoft.com/technet/security/advisory/947563.mspx</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39699" source="XF">microsoft-excel-unspecified-code-execution(39699)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0846/references" source="VUPEN" adv="1">ADV-2008-0846</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0146" source="VUPEN" adv="1">ADV-2008-0146</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/947563.mspx" source="MSKB" adv="1">947563</ref>
      <ref url="http://securitytracker.com/id?1019200" source="SECTRACK">1019200</ref>
      <ref url="http://secunia.com/advisories/28506" source="SECUNIA" adv="1">28506</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" source="HP">SSRT080028</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" source="HP">SSRT080028</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5546" source="OVAL" sig="1">oval:org.mitre.oval:def:5546</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" edition="sp3"/>
        <vers num="2002" edition="sp3"/>
        <vers num="2003" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0082" published="2008-08-12" name="CVE-2008-0082" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">An ActiveX control (Messenger.UIAutomation.1) in Windows Messenger 4.7 and 5.1 is marked as safe-for-scripting, which allows remote attackers to control the Messenger application, and "change state," obtain contact information, and establish audio or video connections without notification via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-225A.html" source="CERT">TA08-225A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-050.mspx" source="MS" patch="1">MS08-050</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/2354" source="VUPEN">ADV-2008-2354</ref>
      <ref url="http://www.securitytracker.com/id?1020681" source="SECTRACK">1020681</ref>
      <ref url="http://www.securityfocus.com/bid/30551" source="BID">30551</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/495467/100/0/threaded" source="BUGTRAQ">20080814 Microsoft Windows Messenger Remote Illegal Access Vulnerability</ref>
      <ref url="http://secunia.com/advisories/31446" source="SECUNIA" adv="1">31446</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5995" source="OVAL">oval:org.mitre.oval:def:5995</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=121915960406986&amp;w=2" source="HP">HPSBST02360</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=121915960406986&amp;w=2" source="HP">HPSBST02360</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_messenger">
        <vers num="4.7"/>
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0083" published="2008-04-08" name="CVE-2008-0083" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The (1) VBScript (VBScript.dll) and (2) JScript (JScript.dll) scripting engines 5.1 and 5.6, as used in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, do not properly decode script, which allows remote attackers to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-099A.html" source="CERT">TA08-099A</ref>
      <ref url="http://www.securityfocus.com/bid/28551" source="BID" patch="1">28551</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-022.mspx" source="MS" patch="1" adv="1">MS08-022</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1146/references" source="VUPEN" adv="1">ADV-2008-1146</ref>
      <ref url="http://www.securitytracker.com/id?1019799" source="SECTRACK">1019799</ref>
      <ref url="http://secunia.com/advisories/29712" source="SECUNIA" adv="1">29712</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5495" source="OVAL">oval:org.mitre.oval:def:5495</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120845064910729&amp;w=2" source="HP">SSRT080048</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120845064910729&amp;w=2" source="HP">HPSBST02329</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:itanium"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0084" published="2008-02-12" name="CVE-2008-0084" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the TCP/IP support in Microsoft Windows Vista allows remote DHCP servers to cause a denial of service (hang and restart) via a crafted DHCP packet.</descript>
    </desc>
    <sols>
      <sol source="nvd">Apply patches.

Windows Vista:
http://www.microsoft.com/downloads/de...=8ce9608b-7049-47cd-adc4-22a803877d33

Windows Vista x64 Edition:
http://www.microsoft.com/downloads/de...=d7b9c3d1-9c23-4e05-bac6-d0b327feaf53</sol>
    </sols>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" source="CERT">TA08-043C</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0506/references" source="VUPEN">ADV-2008-0506</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">SSRT080016</ref>
      <ref url="http://www.securitytracker.com/id?1019383" source="SECTRACK">1019383</ref>
      <ref url="http://www.securityfocus.com/bid/27634" source="BID">27634</ref>
      <ref url="http://secunia.com/advisories/28828" source="SECUNIA">28828</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">SSRT080016</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5240" source="OVAL" sig="1">oval:org.mitre.oval:def:5240</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_vista">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0085" published="2008-07-08" name="CVE-2008-0085" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 does not initialize memory pages when reallocating memory, which allows database operators to obtain sensitive information (database contents) via unknown vectors related to memory page reuse.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-190A.html" source="CERT">TA08-190A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-040.mspx" source="MS" patch="1" adv="1">MS08-040</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/2022/references" source="VUPEN" adv="1">ADV-2008-2022</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securitytracker.com/id?1020441" source="SECTRACK">1020441</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://secunia.com/advisories/30970" source="SECUNIA" adv="1">30970</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14213" source="OVAL">oval:org.mitre.oval:def:14213</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="data_engine">
        <vers num="1.0" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="sql_server">
        <vers num="2000" edition="sp4"/>
        <vers num="2000" edition="sp4:itanium"/>
        <vers num="2005" edition="sp1"/>
        <vers num="2005" edition="sp1:x64"/>
        <vers num="2005" edition="sp1:itanium"/>
        <vers num="2005" edition="sp1:express"/>
        <vers num="2005" edition="sp2"/>
        <vers num="2005" edition="sp2:x64"/>
        <vers num="2005" edition="sp2:itanium"/>
        <vers num="2005" edition="sp2:express"/>
        <vers num="7.0" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="sql_server_desktop_engine">
        <vers num="2000" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="wmsde">
        <vers num="2000"/>
      </prod>
      <prod vendor="microsoft" name="wyukon">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64"/>
        <vers num="" edition=":x32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0086" published="2008-07-08" name="CVE-2008-0086" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4, and 2000 Desktop Engine (WMSDE) allows remote authenticated users to execute arbitrary code via a crafted SQL expression.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-190A.html" source="CERT">TA08-190A</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/2022/references" source="VUPEN">ADV-2008-2022</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securitytracker.com/id?1020441" source="SECTRACK">1020441</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/494082/100/0/threaded" source="BUGTRAQ">20080708 Re: [Full-disclosure] iDefense Security Advisory 07.08.08: Microsoft SQL Server Restore Integer Underflow Vulnerability</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-040.mspx" source="MS">MS08-040</ref>
      <ref url="http://secunia.com/advisories/30970" source="SECUNIA">30970</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14052" source="OVAL">oval:org.mitre.oval:def:14052</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="data_engine">
        <vers num="1.0" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="sql_server">
        <vers num="2000" edition="sp4"/>
        <vers num="2005" edition="sp2"/>
        <vers num="7.0" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="sql_server_desktop_engine">
        <vers num="2000" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="sql_server_express_edition">
        <vers num="2005" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0087" published="2008-04-08" name="CVE-2008-0087" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:C/A:C)" CVSS_score="8.8" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="8.6" CVSS_base_score="8.8">
    <desc>
      <descript source="cve">The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows remote attackers to spoof DNS responses.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-099A.html" source="CERT">TA08-099A</ref>
      <ref url="http://www.securityfocus.com/bid/28553" source="BID" patch="1">28553</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1144/references" source="VUPEN">ADV-2008-1144</ref>
      <ref url="http://www.trusteer.com/docs/windowsresolver.html" source="MISC">http://www.trusteer.com/docs/windowsresolver.html</ref>
      <ref url="http://www.securitytracker.com/id?1019802" source="SECTRACK">1019802</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/490575/100/0/threaded" source="BUGTRAQ">20080408 Microsoft Windows DNS Stub Resolver Cache Poisoning (MS08-020)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-020.mspx" source="MS">MS08-020</ref>
      <ref url="http://secunia.com/advisories/29696" source="SECUNIA" adv="1">29696</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5314" source="OVAL">oval:org.mitre.oval:def:5314</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120845064910729&amp;w=2" source="HP">SSRT080048</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120845064910729&amp;w=2" source="HP">HPSBST02329</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows-nt">
        <vers num="vista"/>
        <vers num="xp" edition=""/>
        <vers num="xp" edition=":pro"/>
        <vers num="xp" edition=":pro:x64"/>
        <vers num="xp" edition="sp2"/>
        <vers num="xp" edition="sp2:pro"/>
        <vers num="xp" edition="sp2:pro:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:itanium"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0088" published="2008-02-12" name="CVE-2008-0088" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:C)" CVSS_score="6.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.0" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Active Directory on Microsoft Windows 2000 and Windows Server 2003, and Active Directory Application Mode (ADAM) on XP and Server 2003, allows remote attackers to cause a denial of service (hang and restart) via a crafted LDAP request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" source="CERT">TA08-043C</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0505/references" source="VUPEN">ADV-2008-0505</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-003.mspx" source="MS">MS08-003</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">SSRT080016</ref>
      <ref url="http://www.securitytracker.com/id?1019382" source="SECTRACK">1019382</ref>
      <ref url="http://www.securityfocus.com/bid/27638" source="BID">27638</ref>
      <ref url="http://secunia.com/advisories/28764" source="SECUNIA">28764</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">HPSBST02314</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5181" source="OVAL" sig="1">oval:org.mitre.oval:def:5181</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:server"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="sp1"/>
        <vers num="sp2"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0089" published="2008-01-03" name="CVE-2008-0089" modified="2009-09-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in uprofile.php in ClipShare allows remote attackers to execute arbitrary SQL commands via the UID parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27108" source="BID">27108</ref>
      <ref url="http://www.milw0rm.com/exploits/4830" source="MILW0RM">4830</ref>
      <ref url="http://secunia.com/advisories/28313" source="SECUNIA">28313</ref>
      <ref url="http://osvdb.org/40077" source="OSVDB">40077</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39364" source="XF">clipshare-uprofile-sql-injection(39364)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clip-share" name="clipshare">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0090" published="2008-01-03" name="CVE-2008-0090" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">A certain ActiveX control in npUpload.dll in DivX Player 6.6.0 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long argument to the SetPassword method.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27106" source="BID">27106</ref>
      <ref url="http://www.milw0rm.com/exploits/4829" source="MILW0RM">4829</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39386" source="XF">divxwebplayer-npUpload-dos(39386)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="divx" name="divx_player">
        <vers num="6.6.0"/>
      </prod>
      <prod vendor="microsoft" name="ie">
        <vers num="7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0091" published="2008-01-03" name="CVE-2008-0091" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in download2.php in AGENCY4NET WEBFTP 1 allows remote attackers to read and delete arbitrary files via a .. (dot dot) in the file parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0051" source="VUPEN">ADV-2008-0051</ref>
      <ref url="http://www.securityfocus.com/bid/27092" source="BID">27092</ref>
      <ref url="http://www.milw0rm.com/exploits/4828" source="MILW0RM">4828</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2008-January/001865.html" source="VIM">20080104 true: AGENCY4NET WEBFTP directory traversal; deletion possible</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39343" source="XF">agency4net-download2-directory-traversal(39343)</ref>
      <ref url="http://secunia.com/advisories/28309" source="SECUNIA">28309</ref>
    </refs>
    <vuln_soft>
      <prod vendor="agency4net" name="webftp">
        <vers num="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0092" published="2008-01-03" name="CVE-2008-0092" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in the search module in Appalachian State University phpWebSite 1.4.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27090" source="BID">27090</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485704/100/0/threaded" source="BUGTRAQ">20080101 Cross-Site Scripting (XSS) in phpWebSite 1.4.0 search</ref>
      <ref url="http://phpwebsite.appstate.edu/blog/2143" source="CONFIRM">http://phpwebsite.appstate.edu/blog/2143</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39391" source="XF">phpwebsite-search-xss(39391)</ref>
      <ref url="http://securityreason.com/securityalert/3511" source="SREASON">3511</ref>
      <ref url="http://secunia.com/advisories/28303" source="SECUNIA">28303</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpwebsite" name="phpwebsite">
        <vers num="1.4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0093" published="2008-01-07" name="CVE-2008-0093" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in newticket.php in eTicket 1.5.5.2, and 1.5.6 RC2 and RC3, allow remote attackers to inject arbitrary web script or HTML via the (1) Name and (2) Subject parameters.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.digitrustgroup.com/advisories/web-application-security-eticket.html" source="MISC">http://www.digitrustgroup.com/advisories/web-application-security-eticket.html</ref>
      <ref url="http://secunia.com/advisories/28331" source="SECUNIA" adv="1">28331</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39400" source="XF">eticket-name-subject-xss(39400)</ref>
      <ref url="http://www.securityfocus.com/bid/27130" source="BID">27130</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eticket" name="eticket">
        <vers num="1.5.5.2"/>
        <vers num="1.5.6_rc2"/>
        <vers num="1.5.6_rc3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0094" published="2008-01-07" name="CVE-2008-0094" modified="2008-10-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in MODx Content Management System 0.9.6.1 allow remote attackers to (1) include and execute arbitrary local files via a .. (dot dot) in the as_language parameter to assets/snippets/AjaxSearch/AjaxSearch.php, reached through index-ajax.php; and (2) read arbitrary local files via a .. (dot dot) in the file parameter to assets/js/htcmime.php.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/28220" source="SECUNIA" patch="1" adv="1">28220</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39352" source="XF">modx-ajaxsearch-file-include(39352)</ref>
      <ref url="http://www.securityfocus.com/bid/27097" source="BID">27097</ref>
      <ref url="http://www.securityfocus.com/bid/27096" source="BID">27096</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485707/100/0/threaded" source="BUGTRAQ">20080102 MODx CMS Source code disclosure, local file inclusion</ref>
      <ref url="http://modxcms.com/forums/index.php/topic,21290.0.html" source="CONFIRM">http://modxcms.com/forums/index.php/topic,21290.0.html</ref>
      <ref url="http://securityreason.com/securityalert/3522" source="SREASON">3522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="modxcms" name="modxcms">
        <vers num="0.9.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0095" published="2008-01-07" name="CVE-2008-0095" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Appliance Developer Kit before Asterisk 1.4 revision 95946, and Appliance s800i 1.0.x before 1.0.3.4 allows remote attackers to cause a denial of service (daemon crash) via a BYE message with an Also (Also transfer) header, which triggers a NULL pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27110" source="BID" patch="1">27110</ref>
      <ref url="http://secunia.com/advisories/28312" source="SECUNIA" patch="1" adv="1">28312</ref>
      <ref url="http://downloads.digium.com/pub/security/AST-2008-001.html" source="CONFIRM" patch="1">http://downloads.digium.com/pub/security/AST-2008-001.html</ref>
      <ref url="http://bugs.digium.com/view.php?id=11637" source="MISC" patch="1">http://bugs.digium.com/view.php?id=11637</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00167.html" source="FEDORA">FEDORA-2008-0199</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00166.html" source="FEDORA">FEDORA-2008-0198</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39361" source="XF">asterisk-bye-also-dos(39361)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0019" source="VUPEN">ADV-2008-0019</ref>
      <ref url="http://www.securitytracker.com/id?1019152" source="SECTRACK">1019152</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485727/100/0/threaded" source="BUGTRAQ">20080102 AST-2008-001: Crash from transfer using BYE with Also header</ref>
      <ref url="http://secunia.com/advisories/28299" source="SECUNIA">28299</ref>
      <ref url="http://securityreason.com/securityalert/3520" source="SREASON">3520</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asterisk" name="asterisk_appliance_developer_kit">
        <vers prev="1" num="1.4_revision_95945"/>
      </prod>
      <prod vendor="asterisk" name="asterisk_business_edition">
        <vers prev="1" num="c.1.0beta7"/>
      </prod>
      <prod vendor="asterisk" name="asterisknow">
        <vers prev="1" num="beta_6"/>
      </prod>
      <prod vendor="asterisk" name="open_source">
        <vers prev="1" num="1.4.16"/>
      </prod>
      <prod vendor="asterisk" name="s800i">
        <vers prev="1" num="1.0.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0096" published="2008-01-07" name="CVE-2008-0096" modified="2009-09-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allow remote attackers to execute arbitrary code via a (1) a long username, which triggers an overflow in the log function; or (2) a long password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27103" source="BID">27103</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485725/100/0/threaded" source="BUGTRAQ">20080102 Multiple vulnerabilities in Georgia SoftWorks SSH2 Server 7.01.0003</ref>
      <ref url="http://secunia.com/advisories/28307" source="SECUNIA">28307</ref>
      <ref url="http://aluigi.altervista.org/adv/gswsshit-adv.txt" source="MISC">http://aluigi.altervista.org/adv/gswsshit-adv.txt</ref>
      <ref url="http://securityreason.com/securityalert/3517" source="SREASON">3517</ref>
    </refs>
    <vuln_soft>
      <prod vendor="georgia_softworks" name="ssh2_server">
        <vers prev="1" num="7.01.0003"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0097" published="2008-01-07" name="CVE-2008-0097" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the log function in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username field, as demonstrated by a certain LoginPassword message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485725/100/0/threaded" source="BUGTRAQ">20080102 Multiple vulnerabilities in Georgia SoftWorks SSH2 Server 7.01.0003</ref>
      <ref url="http://secunia.com/advisories/28307" source="SECUNIA" adv="1">28307</ref>
      <ref url="http://aluigi.altervista.org/adv/gswsshit-adv.txt" source="MISC">http://aluigi.altervista.org/adv/gswsshit-adv.txt</ref>
      <ref url="http://securityreason.com/securityalert/3517" source="SREASON">3517</ref>
    </refs>
    <vuln_soft>
      <prod vendor="georgia_softworks" name="ssh2_server">
        <vers prev="1" num="7.01.0003"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0098" published="2008-01-07" name="CVE-2008-0098" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in RealPlayer 11 build 6.0.14.748 allows remote attackers to execute arbitrary code via unspecified vectors.  NOTE: As of 20080103, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0016" source="VUPEN">ADV-2008-0016</ref>
      <ref url="http://www.us-cert.gov/current/index.html#public_exploit_code_for_realplayer" source="MISC">http://www.us-cert.gov/current/index.html#public_exploit_code_for_realplayer</ref>
      <ref url="http://www.securityfocus.com/bid/27091" source="BID">27091</ref>
      <ref url="http://secunia.com/advisories/28276" source="SECUNIA" adv="1">28276</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2008-January/004811.html" source="MLIST">[Dailydave] 20080101 0day RealPlayer exploit demo</ref>
      <ref url="http://gleg.net/realplayer11.html" source="MISC">http://gleg.net/realplayer11.html</ref>
      <ref url="http://www.securitytracker.com/id?1019153" source="SECTRACK">1019153</ref>
    </refs>
    <vuln_soft>
      <prod vendor="real" name="realplayer">
        <vers num="11_build_6.0.14.748"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0099" published="2008-01-07" name="CVE-2008-0099" modified="2009-09-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the searchtext parameter to search.php, and unspecified other vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27118" source="BID">27118</ref>
      <ref url="http://www.milw0rm.com/exploits/4831" source="MILW0RM">4831</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myphp_forum" name="myphp_forum">
        <vers prev="1" num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0100" published="2008-01-07" name="CVE-2008-0100" modified="2008-10-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the Scene::errorf function in Scene.cpp in White_Dune 0.29 beta791 and earlier allows remote attackers to execute arbitrary code via a long string in a .WRL file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27102" source="BID" patch="1">27102</ref>
      <ref url="http://secunia.com/advisories/28287" source="SECUNIA" patch="1" adv="1">28287</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39385" source="XF">whitedune-sceneerrorf-bo(39385)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485724/100/0/threaded" source="BUGTRAQ">20080102 Buffer-overflow and format string in White_Dune 0.29beta791</ref>
      <ref url="http://vrml.cip.ica.uni-stuttgart.de/dune/news.html" source="CONFIRM">http://vrml.cip.ica.uni-stuttgart.de/dune/news.html</ref>
      <ref url="http://aluigi.altervista.org/adv/whitedunboffs-adv.txt" source="MISC">http://aluigi.altervista.org/adv/whitedunboffs-adv.txt</ref>
      <ref url="http://securityreason.com/securityalert/3516" source="SREASON">3516</ref>
    </refs>
    <vuln_soft>
      <prod vendor="white_dune" name="white_dune">
        <vers prev="1" num="0.29beta791"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0101" published="2008-01-07" name="CVE-2008-0101" modified="2008-10-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the swDebugf function in DuneApp.cpp in White_Dune 0.29 beta791 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a .WRL file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27102" source="BID" patch="1">27102</ref>
      <ref url="http://secunia.com/advisories/28287" source="SECUNIA" patch="1">28287</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39388" source="XF">whitedune-swdegugf-format-string(39388)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485724/100/0/threaded" source="BUGTRAQ">20080102 Buffer-overflow and format string in White_Dune 0.29beta791</ref>
      <ref url="http://vrml.cip.ica.uni-stuttgart.de/dune/news.html" source="CONFIRM">http://vrml.cip.ica.uni-stuttgart.de/dune/news.html</ref>
      <ref url="http://aluigi.altervista.org/adv/whitedunboffs-adv.txt" source="MISC">http://aluigi.altervista.org/adv/whitedunboffs-adv.txt</ref>
      <ref url="http://securityreason.com/securityalert/3516" source="SREASON">3516</ref>
    </refs>
    <vuln_soft>
      <prod vendor="white_dune" name="white_dune">
        <vers prev="1" num="0.29beta791"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0102" published="2008-02-12" name="CVE-2008-0102" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, related to invalid "memory values," aka "Publisher Invalid Memory Reference Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" source="CERT">TA08-043C</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-012.mspx" source="MS" patch="1">MS08-012</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0514/references" source="VUPEN">ADV-2008-0514</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">SSRT080016</ref>
      <ref url="http://www.securitytracker.com/id?1019376" source="SECTRACK">1019376</ref>
      <ref url="http://www.securityfocus.com/bid/27739" source="BID">27739</ref>
      <ref url="http://secunia.com/advisories/28906" source="SECUNIA">28906</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">HPSBST02314</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5305" source="OVAL" sig="1">oval:org.mitre.oval:def:5305</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="publisher">
        <vers num="2000"/>
        <vers num="2002"/>
        <vers num="2003" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0103" published="2008-02-12" name="CVE-2008-0103" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Office document that contains a malformed object, related to a "memory handling error," aka "Microsoft Office Execution Jump Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" source="CERT">TA08-043C</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-013.mspx" source="MS" patch="1">MS08-013</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0515/references" source="VUPEN">ADV-2008-0515</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">SSRT080016</ref>
      <ref url="http://www.securitytracker.com/id?1019375" source="SECTRACK">1019375</ref>
      <ref url="http://www.securityfocus.com/bid/27738" source="BID">27738</ref>
      <ref url="http://secunia.com/advisories/28909" source="SECUNIA">28909</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">SSRT080016</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5407" source="OVAL" sig="1">oval:org.mitre.oval:def:5407</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp2"/>
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac+os"/>
        <vers num="xp" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0104" published="2008-02-12" name="CVE-2008-0104" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, aka "Publisher Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" source="CERT">TA08-043C</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0514/references" source="VUPEN">ADV-2008-0514</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-012.mspx" source="MS">MS08-012</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">SSRT080016</ref>
      <ref url="http://www.securitytracker.com/id?1019377" source="SECTRACK">1019377</ref>
      <ref url="http://www.securityfocus.com/bid/27740" source="BID">27740</ref>
      <ref url="http://secunia.com/advisories/28906" source="SECUNIA">28906</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">SSRT080016</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4547" source="OVAL" sig="1">oval:org.mitre.oval:def:4547</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000"/>
        <vers num="2002"/>
        <vers num="2003" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="publisher">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0105" published="2008-02-12" name="CVE-2008-0105" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section header index table information, aka "Microsoft Works File Converter Index Table Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" source="CERT">TA08-043C</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0513/references" source="VUPEN">ADV-2008-0513</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-011.mspx" source="MS">MS08-011</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">SSRT080016</ref>
      <ref url="http://www.securitytracker.com/id?1019387" source="SECTRACK">1019387</ref>
      <ref url="http://www.securityfocus.com/bid/27658" source="BID">27658</ref>
      <ref url="http://secunia.com/advisories/28904" source="SECUNIA">28904</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">SSRT080016</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5009" source="OVAL" sig="1">oval:org.mitre.oval:def:5009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2003" edition="sp2"/>
        <vers num="2003" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2005"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0106" published="2008-07-08" name="CVE-2008-0106" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft SQL Server 2005 SP1 and SP2, and 2005 Express Edition SP1 and SP2, allows remote authenticated users to execute arbitrary code via a crafted insert statement.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-190A.html" source="CERT">TA08-190A</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/2022/references" source="VUPEN">ADV-2008-2022</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securitytracker.com/id?1020441" source="SECTRACK">1020441</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/494082/100/0/threaded" source="BUGTRAQ">20080708 Re: [Full-disclosure] iDefense Security Advisory 07.08.08: Microsoft SQL Server Restore Integer Underflow Vulnerability</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-040.mspx" source="MS">MS08-040</ref>
      <ref url="http://secunia.com/advisories/30970" source="SECUNIA">30970</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13785" source="OVAL">oval:org.mitre.oval:def:13785</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="data_engine">
        <vers num="1.0" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="sql_server">
        <vers num="2000" edition="sp4"/>
        <vers num="2005" edition="sp2"/>
        <vers num="7.0" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="sql_server_desktop_engine">
        <vers num="2000" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="sql_server_express_edition">
        <vers num="2005" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0107" published="2008-07-08" name="CVE-2008-0107" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Integer underflow in SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 allows remote authenticated users to execute arbitrary code via a (1) SMB or (2) WebDAV pathname for an on-disk file (aka stored backup file) with a crafted record size value, which triggers a heap-based buffer overflow, aka "SQL Server Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-190A.html" source="CERT">TA08-190A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-040.mspx" source="MS" patch="1" adv="1">MS08-040</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/2022/references" source="VUPEN" adv="1">ADV-2008-2022</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securitytracker.com/id?1020441" source="SECTRACK">1020441</ref>
      <ref url="http://www.securityfocus.com/bid/30119" source="BID">30119</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/494082/100/0/threaded" source="BUGTRAQ">20080708 Re: [Full-disclosure] iDefense Security Advisory 07.08.08: Microsoft SQL Server Restore Integer Underflow Vulnerability</ref>
      <ref url="http://www.insomniasec.com/advisories/ISVA-080709.1.htm" source="MISC">http://www.insomniasec.com/advisories/ISVA-080709.1.htm</ref>
      <ref url="http://secunia.com/advisories/30970" source="SECUNIA" adv="1">30970</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13936" source="OVAL">oval:org.mitre.oval:def:13936</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=723" source="IDEFENSE">20080708 Microsoft SQL Server Restore Integer Underflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="data_engine">
        <vers num="1.0" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="sql_server">
        <vers num="2000" edition="sp4"/>
        <vers num="2000" edition="sp4:itanium"/>
        <vers num="2005" edition="sp1"/>
        <vers num="2005" edition="sp1:x64"/>
        <vers num="2005" edition="sp1:itanium"/>
        <vers num="2005" edition="sp1:express"/>
        <vers num="2005" edition="sp2"/>
        <vers num="2005" edition="sp2:x64"/>
        <vers num="2005" edition="sp2:itanium"/>
        <vers num="2005" edition="sp2:express"/>
        <vers num="7.0" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="sql_server_desktop_engine">
        <vers num="2000" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="wmsde">
        <vers num="2000"/>
      </prod>
      <prod vendor="microsoft" name="wyukon">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64"/>
        <vers num="" edition=":x32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0108" published="2008-02-12" name="CVE-2008-0108" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted field lengths, aka "Microsoft Works File Converter Field Length Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" source="CERT">TA08-043C</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0513/references" source="VUPEN" adv="1">ADV-2008-0513</ref>
      <ref url="http://www.securitytracker.com/id?1019388" source="SECTRACK">1019388</ref>
      <ref url="http://www.securityfocus.com/bid/27659" source="BID">27659</ref>
      <ref url="http://www.milw0rm.com/exploits/5107" source="MILW0RM">5107</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-011.mspx" source="MS">MS08-011</ref>
      <ref url="http://secunia.com/advisories/28904" source="SECUNIA" adv="1">28904</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">SSRT080016</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">SSRT080016</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=660" source="IDEFENSE">20080208 Microsoft Office Works Converter Stack-based Buffer Overflow Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5202" source="OVAL" sig="1">oval:org.mitre.oval:def:5202</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2003" edition="sp2"/>
        <vers num="2003" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2005"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0109" published="2008-02-12" name="CVE-2008-0109" modified="2011-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Word in Microsoft Office 2000 SP3, XP SP3, Office 2003 SP2, and Office Word Viewer 2003 allows remote attackers to execute arbitrary code via crafted fields within the File Information Block (FIB) of a Word file, which triggers length calculation errors and memory corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" source="CERT">TA08-043C</ref>
      <ref url="http://www.kb.cert.org/vuls/id/692417" source="CERT-VN">VU#692417</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-009.mspx" source="MS" patch="1" adv="1">MS08-009</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0511/references" source="VUPEN" adv="1">ADV-2008-0511</ref>
      <ref url="http://www.securitytracker.com/id?1019374" source="SECTRACK">1019374</ref>
      <ref url="http://www.securityfocus.com/bid/27656" source="BID">27656</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488071/100/0/threaded" source="BUGTRAQ">20080213 [Reversemode Advisory] February Advisories : Microsoft Word 2003 + Fortinet Forticlient</ref>
      <ref url="http://secunia.com/advisories/28901" source="SECUNIA" adv="1">28901</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">SSRT080016</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">SSRT080016</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5073" source="OVAL" sig="1">oval:org.mitre.oval:def:5073</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp2"/>
        <vers num="xp" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="word">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0110" published="2008-03-11" name="CVE-2008-0110" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Outlook in Office 2000 SP3, XP SP3, 2003 SP2 and Sp3, and Office System allows user-assisted remote attackers to execute arbitrary code via a crafted mailto URI.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-071A.html" source="CERT">TA08-071A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/393305" source="CERT-VN">VU#393305</ref>
      <ref url="http://www.securityfocus.com/bid/28147" source="BID" patch="1">28147</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-015.mspx" source="MS" patch="1">MS08-015</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0847/references" source="VUPEN">ADV-2008-0847</ref>
      <ref url="http://www.securitytracker.com/id?1019579" source="SECTRACK">1019579</ref>
      <ref url="http://secunia.com/advisories/29320" source="SECUNIA" adv="1">29320</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" source="HP">HPSBST02320</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" source="HP">HPSBST02320</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5278" source="OVAL" sig="1">oval:org.mitre.oval:def:5278</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp2"/>
        <vers num="2003" edition="sp3"/>
        <vers num="2007"/>
        <vers num="xp" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0111" published="2008-03-11" name="CVE-2008-0111" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted data validation records, aka "Excel Data Validation Record Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-071A.html" source="CERT" patch="1">TA08-071A</ref>
      <ref url="http://www.securityfocus.com/bid/28094" source="BID" patch="1">28094</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-014.mspx" source="MS" patch="1">MS08-014</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0846/references" source="VUPEN">ADV-2008-0846</ref>
      <ref url="http://www.securitytracker.com/id?1019582" source="SECTRACK">1019582</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" source="HP">SSRT080028</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" source="HP">HPSBST02320</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5114" source="OVAL" sig="1">oval:org.mitre.oval:def:5114</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" edition="sp3"/>
        <vers num="2002" edition="sp3"/>
        <vers num="2003" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
        <vers num="2007"/>
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack_for_word_excel_ppt_2007">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0112" published="2008-03-11" name="CVE-2008-0112" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Excel 2000 SP3, and Office for Mac 2004 and 2008 allows user-assisted remote attackers to execute arbitrary code via a crafted .SLK file that is not properly handled when importing the file, aka "Excel File Import Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-071A.html" source="CERT" patch="1">TA08-071A</ref>
      <ref url="http://www.securityfocus.com/bid/28095" source="BID" patch="1">28095</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-014.mspx" source="MS" patch="1">MS08-014</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0846/references" source="VUPEN">ADV-2008-0846</ref>
      <ref url="http://www.securitytracker.com/id?1019583" source="SECTRACK">1019583</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" source="HP">SSRT080028</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" source="HP">HPSBST02320</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5284" source="OVAL" sig="1">oval:org.mitre.oval:def:5284</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
        <vers num="2008" edition=""/>
        <vers num="2008" edition=":mac"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0113" published="2008-03-11" name="CVE-2008-0113" modified="2011-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Office Excel Viewer 2003 up to SP3 allows user-assisted remote attackers to execute arbitrary code via an Excel document with malformed cell comments that trigger memory corruption from an "allocation error," aka "Microsoft Office Cell Parsing Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-071A.html" source="CERT">TA08-071A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-016.mspx" source="MS" patch="1" adv="1">MS08-016</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-08-008" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-08-008</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0848/references" source="VUPEN" adv="1">ADV-2008-0848</ref>
      <ref url="http://www.securitytracker.com/id?1019578" source="SECTRACK">1019578</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/489415/100/0/threaded" source="BUGTRAQ">20080311 ZDI-08-008: Microsoft Excel BIFF File Format Cell Record Parsing Memory Corruption Vulnerability</ref>
      <ref url="http://secunia.com/advisories/29321" source="SECUNIA" adv="1">29321</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" source="HP">HPSBST02320</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" source="HP">HPSBST02320</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5421" source="OVAL" sig="1">oval:org.mitre.oval:def:5421</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0114" published="2008-03-11" name="CVE-2008-0114" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via crafted Style records that trigger memory corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-071A.html" source="CERT" patch="1">TA08-071A</ref>
      <ref url="http://www.securityfocus.com/bid/28166" source="BID" patch="1">28166</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-014.mspx" source="MS" patch="1">MS08-014</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0846/references" source="VUPEN">ADV-2008-0846</ref>
      <ref url="http://www.securitytracker.com/id?1019584" source="SECTRACK">1019584</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" source="HP">HPSBST02320</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" source="HP">HPSBST02320</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5456" source="OVAL" sig="1">oval:org.mitre.oval:def:5456</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" edition="sp3"/>
        <vers num="2002" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0115" published="2008-03-11" name="CVE-2008-0115" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via malformed formulas, aka "Excel Formula Parsing Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-071A.html" source="CERT" patch="1">TA08-071A</ref>
      <ref url="http://www.securityfocus.com/bid/28167" source="BID" patch="1">28167</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-014.mspx" source="MS" patch="1">MS08-014</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0846/references" source="VUPEN">ADV-2008-0846</ref>
      <ref url="http://www.securitytracker.com/id?1019585" source="SECTRACK">1019585</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" source="HP">HPSBST02320</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" source="HP">HPSBST02320</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5512" source="OVAL" sig="1">oval:org.mitre.oval:def:5512</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" edition="sp3"/>
        <vers num="2002" edition="sp3"/>
        <vers num="2003" edition="sp2"/>
        <vers num="2007"/>
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack_for_word_excel_ppt_2007">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0116" published="2008-03-11" name="CVE-2008-0116" modified="2011-04-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, Compatibility Pack, and Office 2004 and 2008 for Mac allows user-assisted remote attackers to execute arbitrary code via malformed tags in rich text, aka "Excel Rich Text Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-071A.html" source="CERT" patch="1">TA08-071A</ref>
      <ref url="http://www.securityfocus.com/bid/28168" source="BID" patch="1">28168</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-014.mspx" source="MS" patch="1">MS08-014</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0846/references" source="VUPEN" adv="1">ADV-2008-0846</ref>
      <ref url="http://www.securitytracker.com/id?1019586" source="SECTRACK">1019586</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/489430/100/0/threaded" source="BUGTRAQ">20080311 TPTI-08-03: Microsoft Excel Rich Text Memory Corruption Vulnerability</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" source="HP">HPSBST02320</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" source="HP">HPSBST02320</ref>
      <ref url="http://dvlabs.tippingpoint.com/advisory/TPTI-08-03" source="MISC">http://dvlabs.tippingpoint.com/advisory/TPTI-08-03</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5212" source="OVAL" sig="1">oval:org.mitre.oval:def:5212</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" edition="sp3"/>
        <vers num="2002" edition="sp3"/>
        <vers num="2003" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
        <vers num="2008" edition=""/>
        <vers num="2008" edition=":mac"/>
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack_for_word_excel_ppt_2007">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0117" published="2008-03-11" name="CVE-2008-0117" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Excel 2000 SP3 and 2002 SP2, and Office 2004 and 2008 for Mac, allows user-assisted remote attackers to execute arbitrary code via crafted conditional formatting values, aka "Excel Conditional Formatting Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-071A.html" source="CERT" patch="1">TA08-071A</ref>
      <ref url="http://www.securityfocus.com/bid/28170" source="BID" patch="1">28170</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-014.mspx" source="MS" patch="1">MS08-014</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0846/references" source="VUPEN">ADV-2008-0846</ref>
      <ref url="http://www.securitytracker.com/id?1019587" source="SECTRACK">1019587</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" source="HP">SSRT080028</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" source="HP">HPSBST02320</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5508" source="OVAL" sig="1">oval:org.mitre.oval:def:5508</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="compatibility_pack_word_excel_powerpoint_2007">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" edition="sp3"/>
        <vers num="2002" edition="sp3"/>
        <vers num="2003" edition="sp2"/>
        <vers num="2007"/>
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp2"/>
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
        <vers num="2007"/>
        <vers num="2008" edition=""/>
        <vers num="2008" edition=":mac"/>
        <vers num="xp" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0118" published="2008-03-11" name="CVE-2008-0118" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, Excel Viewer 2003 up to SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption from an "allocation error," aka "Microsoft Office Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-071A.html" source="CERT" patch="1">TA08-071A</ref>
      <ref url="http://www.securityfocus.com/bid/28146" source="BID" patch="1">28146</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-016.mspx" source="MS" patch="1">MS08-016</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0848/references" source="VUPEN">ADV-2008-0848</ref>
      <ref url="http://www.securitytracker.com/id?1019578" source="SECTRACK">1019578</ref>
      <ref url="http://secunia.com/advisories/29321" source="SECUNIA" adv="1">29321</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" source="HP">HPSBST02320</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" source="HP">HPSBST02320</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5190" source="OVAL" sig="1">oval:org.mitre.oval:def:5190</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp2"/>
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
        <vers num="xp" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0119" published="2008-05-13" name="CVE-2008-0119" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Publisher in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 SP1 and earlier allows remote attackers to execute arbitrary code via a Publisher file with crafted object header data that triggers memory corruption, aka "Publisher Object Handler Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-134A.html" source="CERT">TA08-134A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-027.mspx" source="MS" patch="1">MS08-027</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1505/references" source="VUPEN">ADV-2008-1505</ref>
      <ref url="http://www.securitytracker.com/id?1020015" source="SECTRACK">1020015</ref>
      <ref url="http://www.securityfocus.com/bid/29158" source="BID">29158</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/492073/100/0/threaded" source="BUGTRAQ">20080514 Microsoft Office Publisher PUB File Parsing Remote Memory Corruption Vulnerability</ref>
      <ref url="http://secunia.com/advisories/30150" source="SECUNIA" adv="1">30150</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5303" source="OVAL">oval:org.mitre.oval:def:5303</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=121129490723574&amp;w=2" source="HP">HPSBST02336</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=121129490723574&amp;w=2" source="HP">HPSBST02336</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp2"/>
        <vers num="2003" edition="sp3"/>
        <vers num="2007"/>
        <vers num="2007_sp1"/>
        <vers num="xp" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0120" published="2008-08-12" name="CVE-2008-0120" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with a malformed picture index that triggers memory corruption, related to handling of CString objects, aka "Memory Allocation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-225A.html" source="CERT">TA08-225A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-051.mspx" source="MS" patch="1">MS08-051</ref>
      <ref url="http://secunia.com/advisories/31453" source="SECUNIA" patch="1" adv="1">31453</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/2355" source="VUPEN">ADV-2008-2355</ref>
      <ref url="http://www.securitytracker.com/id?1020676" source="SECTRACK">1020676</ref>
      <ref url="http://www.securityfocus.com/bid/30552" source="BID">30552</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5768" source="OVAL">oval:org.mitre.oval:def:5768</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=121915960406986&amp;w=2" source="HP">SSRT080117</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=121915960406986&amp;w=2" source="HP">SSRT080117</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=739" source="IDEFENSE">20080812 Microsoft PowerPoint Viewer 2003 Cstring Integer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_powerpoint_viewer">
        <vers num="2003"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0121" published="2008-08-12" name="CVE-2008-0121" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">A "memory calculation error" in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with an invalid picture index that triggers memory corruption, aka "Memory Calculation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-225A.html" source="CERT">TA08-225A</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/2355" source="VUPEN">ADV-2008-2355</ref>
      <ref url="http://www.securitytracker.com/id?1020676" source="SECTRACK">1020676</ref>
      <ref url="http://www.securityfocus.com/bid/30554" source="BID">30554</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-051.mspx" source="MS">MS08-051</ref>
      <ref url="http://secunia.com/advisories/31453" source="SECUNIA" adv="1">31453</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5724" source="OVAL">oval:org.mitre.oval:def:5724</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=121915960406986&amp;w=2" source="HP">HPSBST02360</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=121915960406986&amp;w=2" source="HP">HPSBST02360</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=738" source="IDEFENSE">20080812 Microsoft PowerPoint Viewer 2003 Out of Bounds Array Index Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_powerpoint_viewer">
        <vers num="2003"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0122" published="2008-01-15" name="CVE-2008-0122" modified="2011-08-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/203611" source="CERT-VN">VU#203611</ref>
      <ref url="http://www.securityfocus.com/bid/27283" source="BID" patch="1">27283</ref>
      <ref url="http://security.freebsd.org/advisories/FreeBSD-SA-08:02.libc.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-08:02</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00782.html" source="FEDORA">FEDORA-2008-0904</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00781.html" source="FEDORA">FEDORA-2008-0903</ref>
      <ref url="https://issues.rpath.com/browse/RPL-2169" source="CONFIRM">https://issues.rpath.com/browse/RPL-2169</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=429149" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=429149</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39670" source="XF">freebsd-inetnetwork-bo(39670)</ref>
      <ref url="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=4167" source="CONFIRM">http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=4167</ref>
      <ref url="http://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&amp;heading=AIX61&amp;path=/200802/SECURITY/20080227/datafile123640&amp;label=AIX%20libc%20inet_network%20buffer%20overflow" source="CONFIRM">http://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&amp;heading=AIX61&amp;path=/200802/SECURITY/20080227/datafile123640&amp;label=AIX%20libc%20inet_network%20buffer%20overflow</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1743/references" source="VUPEN" adv="1">ADV-2008-1743</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0703" source="VUPEN" adv="1">ADV-2008-0703</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0193" source="VUPEN" adv="1">ADV-2008-0193</ref>
      <ref url="http://www.securitytracker.com/id?1019189" source="SECTRACK">1019189</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487000/100/0/threaded" source="BUGTRAQ">20080124 rPSA-2008-0029-1 bind bind-utils</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0300.html" source="REDHAT" adv="1">RHSA-2008:0300</ref>
      <ref url="http://www.isc.org/index.pl?/sw/bind/bind-security.php" source="CONFIRM" adv="1">http://www.isc.org/index.pl?/sw/bind/bind-security.php</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2008-244.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2008-244.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-238493-1" source="SUNALERT">238493</ref>
      <ref url="http://secunia.com/advisories/30718" source="SECUNIA" adv="1">30718</ref>
      <ref url="http://secunia.com/advisories/30538" source="SECUNIA" adv="1">30538</ref>
      <ref url="http://secunia.com/advisories/30313" source="SECUNIA" adv="1">30313</ref>
      <ref url="http://secunia.com/advisories/29323" source="SECUNIA" adv="1">29323</ref>
      <ref url="http://secunia.com/advisories/29161" source="SECUNIA" adv="1">29161</ref>
      <ref url="http://secunia.com/advisories/28579" source="SECUNIA" adv="1">28579</ref>
      <ref url="http://secunia.com/advisories/28487" source="SECUNIA" adv="1">28487</ref>
      <ref url="http://secunia.com/advisories/28429" source="SECUNIA" adv="1">28429</ref>
      <ref url="http://secunia.com/advisories/28367" source="SECUNIA" adv="1">28367</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10190" source="OVAL">oval:org.mitre.oval:def:10190</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html" source="SUSE">SUSE-SR:2008:006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers prev="1" num="9.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0123" published="2008-01-11" name="CVE-2008-0123" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter.  NOTE: this issue only exists until the installation is complete.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0164" source="VUPEN">ADV-2008-0164</ref>
      <ref url="http://int21.de/cve/CVE-2008-0123-moodle.html" source="MISC">http://int21.de/cve/CVE-2008-0123-moodle.html </ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2008-01/0202.html" source="FULLDISC">20080111 Cross site scripting (XSS) in Moodle 1.8.3</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39630" source="XF">moodle-install-xss(39630)</ref>
      <ref url="http://www.securityfocus.com/bid/27259" source="BID">27259</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486198/100/0/threaded" source="BUGTRAQ">20080111 Cross site scripting (XSS) in Moodle 1.8.3</ref>
      <ref url="http://secunia.com/advisories/28838" source="SECUNIA">28838</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html" source="SUSE">SUSE-SR:2008:003</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moodle" name="moodle">
        <vers prev="1" num="1.8.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0124" published="2008-02-28" name="CVE-2008-0124" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Serendipity (S9Y) before 1.3-beta1 allows remote authenticated users to inject arbitrary web script or HTML via (1) the "Real name" field in Personal Settings, which is presented to readers of articles; or (2) a file upload, as demonstrated by a .htm, .html, or .js file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://blog.s9y.org/archives/191-Serendipity-1.3-beta1-released.html" source="CONFIRM" patch="1">http://blog.s9y.org/archives/191-Serendipity-1.3-beta1-released.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40851" source="XF">serendipity-realname-username-xss(40851)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0700/references" source="VUPEN">ADV-2008-0700</ref>
      <ref url="http://www.securitytracker.com/id?1019502" source="SECTRACK">1019502</ref>
      <ref url="http://www.securityfocus.com/bid/28003" source="BID">28003</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1528" source="DEBIAN">DSA-1528</ref>
      <ref url="http://secunia.com/advisories/29502" source="SECUNIA">29502</ref>
      <ref url="http://secunia.com/advisories/29128" source="SECUNIA">29128</ref>
      <ref url="http://int21.de/cve/CVE-2008-0124-s9y.html" source="MISC">http://int21.de/cve/CVE-2008-0124-s9y.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="s9y" name="serendipity">
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.5_pl1"/>
        <vers num="0.6"/>
        <vers num="0.6_pl1"/>
        <vers num="0.6_pl2"/>
        <vers num="0.6_pl3"/>
        <vers num="0.6_rc1"/>
        <vers num="0.6_rc2"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.7_beta1"/>
        <vers num="0.7_beta2"/>
        <vers num="0.7_beta3"/>
        <vers num="0.7_beta4"/>
        <vers num="0.7_rc1"/>
        <vers num="0.8"/>
        <vers num="0.8.1"/>
        <vers num="0.8.2"/>
        <vers num="0.8_beta5"/>
        <vers num="0.8_beta6"/>
        <vers num="0.8_beta_6_snapshot"/>
        <vers num="0.9.1"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0_beta2"/>
        <vers num="1.0_beta3"/>
        <vers num="1.1.1"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.2__beta5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0125" published="2008-03-24" name="CVE-2008-0125" modified="2008-10-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in phpstats.php in Michael Wagner phpstats 0.1 alpha allows remote attackers to inject arbitrary web script or HTML via the baseDir parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/41261" source="XF">phpstats-phpstats-xss(41261)</ref>
      <ref url="http://www.securityfocus.com/bid/28291" source="BID">28291</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/489722/100/0/threaded" source="BUGTRAQ">20080317 Cross Site Scripting (XSS) in phpstats 0.1_alpha, CVE-2008-0125</ref>
      <ref url="http://securityreason.com/securityalert/3765" source="SREASON">3765</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpstats" name="phpstats">
        <vers num="0.1_alpha"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0127" published="2008-01-09" name="CVE-2008-0127" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:C/A:C)" CVSS_score="8.8" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="8.6" CVSS_base_score="8.8">
    <desc>
      <descript source="cve">The administration interface in McAfee E-Business Server 8.5.2 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a long initial authentication packet.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27197" source="BID" patch="1">27197</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486035/100/0/threaded" source="BUGTRAQ" patch="1">20080109 [INFIGO-2008-01-06]: McAfee E-Business Server Remote Preauth Code Execution / DoS - Corrected</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485992/100/0/threaded" source="BUGTRAQ" patch="1">20080109 [INFIGO 2008-01-06]: McAfee E-Business Server Remote Preauth Code Execution / DoS</ref>
      <ref url="https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=614472&amp;sliceId=SAL_Public&amp;command=show&amp;forward=nonthreadedKC&amp;kcId=614472" source="CONFIRM">https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=614472&amp;sliceId=SAL_Public&amp;command=show&amp;forward=nonthreadedKC&amp;kcId=614472</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39563" source="XF">mcafee-ebusiness-packet-code-execution(39563)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39561" source="XF">mcafee-ebusiness-authentication-packet-dos(39561)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0087" source="VUPEN">ADV-2008-0087</ref>
      <ref url="http://www.milw0rm.com/exploits/4878" source="MILW0RM">4878</ref>
      <ref url="http://securitytracker.com/id?1019170" source="SECTRACK">1019170</ref>
      <ref url="http://securityreason.com/securityalert/3530" source="SREASON">3530</ref>
      <ref url="http://secunia.com/advisories/28408" source="SECUNIA">28408</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="e-business_server">
        <vers prev="1" num="8.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0128" published="2008-01-22" name="CVE-2008-0128" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://issues.apache.org/bugzilla/show_bug.cgi?id=41217" source="CONFIRM" patch="1">http://issues.apache.org/bugzilla/show_bug.cgi?id=41217</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39804" source="XF">apache-singlesignon-information-disclosure(39804)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0233" source="VUPEN">ADV-2009-0233</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0192" source="VUPEN">ADV-2008-0192</ref>
      <ref url="http://www.securityfocus.com/bid/27365" source="BID">27365</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500412/100/0/threaded" source="BUGTRAQ">20090127 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities (Updated - v1.1)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500396/100/0/threaded" source="BUGTRAQ">20090124 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities</ref>
      <ref url="http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540" source="CONFIRM">http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540</ref>
      <ref url="http://security-tracker.debian.net/tracker/CVE-2008-0128" source="CONFIRM">http://security-tracker.debian.net/tracker/CVE-2008-0128</ref>
      <ref url="http://secunia.com/advisories/33668" source="SECUNIA">33668</ref>
      <ref url="http://secunia.com/advisories/31493" source="SECUNIA">31493</ref>
      <ref url="http://secunia.com/advisories/28552" source="SECUNIA" adv="1">28552</ref>
      <ref url="http://secunia.com/advisories/28549" source="SECUNIA" adv="1">28549</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2008-0630.html" source="REDHAT">RHSA-2008:0630</ref>
      <ref url="http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx" source="CONFIRM">http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0261.html" source="REDHAT">RHSA-2008:0261</ref>
      <ref url="http://secunia.com/advisories/29242" source="SECUNIA">29242</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html" source="SUSE">SUSE-SR:2008:005</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers prev="1" num="5.5.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0129" published="2008-01-08" name="CVE-2008-0129" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in starnet/addons/slideshow_full.php in Site@School 2.3.10 and earlier allows remote attackers to execute arbitrary SQL commands via the album_name parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/4832" source="MILW0RM">4832</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39417" source="XF">siteatschool-slideshowfull-sql-injection(39417)</ref>
      <ref url="http://www.securityfocus.com/bid/27120" source="BID">27120</ref>
    </refs>
    <vuln_soft>
      <prod vendor="siteatschool" name="siteatschool">
        <vers prev="1" num="2.3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0130" published="2008-01-08" name="CVE-2008-0130" modified="2011-08-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login_form.asp in Instant Softwares Dating Site allows remote attackers to execute arbitrary SQL commands via the Username parameter, a different vulnerability than CVE-2007-6671.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39326" source="XF">dating-site-login-sql-injection(39326)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39326" source="XF">dating-site-login-sql-injection(39326)</ref>
      <ref url="http://secunia.com/advisories/28283" source="SECUNIA" adv="1">28283</ref>
      <ref url="http://osvdb.org/39766" source="OSVDB">39766</ref>
    </refs>
    <vuln_soft>
      <prod vendor="instantsoftwares" name="dating_site">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0131" published="2008-01-08" name="CVE-2008-0131" modified="2009-09-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in login_form.asp in Instant Softwares Dating Site allows remote attackers to inject arbitrary web script or HTML via the msg parameter, a different product than CVE-2006-6022.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27121" source="BID">27121</ref>
      <ref url="http://secunia.com/advisories/28283" source="SECUNIA" adv="1">28283</ref>
    </refs>
    <vuln_soft>
      <prod vendor="instantsoftwares" name="dating_site">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0132" published="2008-01-08" name="CVE-2008-0132" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Pragma FortressSSH 5.0 Build 4 Revision 293 and earlier handles long input to sshd.exe by creating an error-message window and waiting for the administrator to click in this window before terminating the sshd.exe process, which allows remote attackers to cause a denial of service (connection slot exhaustion) via a flood of SSH connections with long data objects, as demonstrated by (1) a long list of keys and (2) a long username.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39354" source="XF">fortressssh-sshd-dos(39354)</ref>
      <ref url="http://aluigi.org/poc/pragmassh.zip" source="MISC">http://aluigi.org/poc/pragmassh.zip</ref>
      <ref url="http://aluigi.altervista.org/adv/pragmassh-adv.txt" source="MISC">http://aluigi.altervista.org/adv/pragmassh-adv.txt</ref>
      <ref url="http://www.securityfocus.com/bid/27141" source="BID">27141</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=119947184730448&amp;w=2" source="BUGTRAQ">20080104 Some DoS in some telnet servers</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pragma_systems" name="fortressssh">
        <vers prev="1" num="5.0_build_4_r_293"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0133" published="2008-01-08" name="CVE-2008-0133" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Tribisur 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to cat_main.php and the (2) cat parameter to forum.php in a liste action.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27149" source="BID">27149</ref>
      <ref url="http://www.milw0rm.com/exploits/4840" source="MILW0RM">4840</ref>
      <ref url="http://secunia.com/advisories/28362" source="SECUNIA">28362</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39443" source="XF">tribisur-catmain-forum-sql-injection(39443)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thomas_perez" name="tribisur">
        <vers prev="1" num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0134" published="2008-01-08" name="CVE-2008-0134" modified="2012-10-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Forums/setup.asp in Snitz Forums 2000 3.4.06 and earlier allows remote attackers to inject arbitrary web script or HTML via the MAIL parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27162" source="BID">27162</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485836/100/200/threaded" source="BUGTRAQ">20080107 [HSC] Snitz Forums Multiple Vulnerabilities</ref>
      <ref url="http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt" source="MISC">http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt</ref>
      <ref url="http://secunia.com/advisories/28284" source="SECUNIA" adv="1">28284</ref>
      <ref url="http://hackerscenter.com/archive/view.asp?id=28145" source="MISC">http://hackerscenter.com/archive/view.asp?id=28145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snitz_communications" name="snitz_forums_2000">
        <vers num="3.0"/>
        <vers num="3.1" edition="sr4"/>
        <vers num="3.2.03"/>
        <vers num="3.3"/>
        <vers num="3.3.01"/>
        <vers num="3.3.02"/>
        <vers num="3.3.03"/>
        <vers num="3.4.02"/>
        <vers num="3.4.03"/>
        <vers num="3.4.04"/>
        <vers num="3.4.05"/>
        <vers prev="1" num="3.4.06"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0135" published="2008-01-08" name="CVE-2008-0135" modified="2012-10-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Snitz Forums 2000 3.4.06 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for forum/snitz_forums_2000.mdb.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485894/100/200/threaded" source="BUGTRAQ">20080107 RE: [HSC] Snitz Forums Multiple Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485836/100/200/threaded" source="BUGTRAQ">20080107 [HSC] Snitz Forums Multiple Vulnerabilities</ref>
      <ref url="http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt" source="MISC">http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt</ref>
      <ref url="http://hackerscenter.com/archive/view.asp?id=28145" source="MISC">http://hackerscenter.com/archive/view.asp?id=28145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snitz_communications" name="snitz_forums_2000">
        <vers num="3.0"/>
        <vers num="3.1" edition="sr4"/>
        <vers num="3.2.03"/>
        <vers num="3.3"/>
        <vers num="3.3.01"/>
        <vers num="3.3.02"/>
        <vers num="3.3.03"/>
        <vers num="3.4.02"/>
        <vers num="3.4.03"/>
        <vers num="3.4.04"/>
        <vers num="3.4.05"/>
        <vers prev="1" num="3.4.06"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0136" published="2008-01-08" name="CVE-2008-0136" modified="2012-10-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Snitz Forums 2000 3.4.05 allows remote attackers to obtain sensitive information via a direct request to forum/whereami.asp, which reveals the database path.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485894/100/200/threaded" source="BUGTRAQ">20080107 RE: [HSC] Snitz Forums Multiple Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485836/100/200/threaded" source="BUGTRAQ">20080107 [HSC] Snitz Forums Multiple Vulnerabilities</ref>
      <ref url="http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt" source="MISC">http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt</ref>
      <ref url="http://hackerscenter.com/archive/view.asp?id=28145" source="MISC">http://hackerscenter.com/archive/view.asp?id=28145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snitz_communications" name="snitz_forums_2000">
        <vers num="3.4.05"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0137" published="2008-01-08" name="CVE-2008-0137" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in config.inc.php in SNETWORKS PHP CLASSIFIEDS 5.0 allows remote attackers to execute arbitrary PHP code via a URL in the path_escape parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0053" source="VUPEN">ADV-2008-0053</ref>
      <ref url="http://www.milw0rm.com/exploits/4838" source="MILW0RM">4838</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39468" source="XF">snetworks-configinc-file-include(39468)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snetworks" name="php_classifieds">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0138" published="2008-01-08" name="CVE-2008-0138" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in xoopsgallery/init_basic.php in the mod_gallery module for XOOPS, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39461" source="XF">xoops-modgallery-zendhashkey-file-include(39461)</ref>
      <ref url="http://www.securityfocus.com/bid/27155" source="BID">27155</ref>
      <ref url="http://www.milw0rm.com/exploits/4847" source="MILW0RM">4847</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xoops" name="xoopsgallery_module">
        <vers num="1.3.3_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0139" published="2008-01-08" name="CVE-2008-0139" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Eval injection vulnerability in loudblog/inc/parse_old.php in Loudblog 0.8.0 and earlier allows remote attackers to execute arbitrary PHP code via the template parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27157" source="BID">27157</ref>
      <ref url="http://secunia.com/advisories/28336" source="SECUNIA" adv="1">28336</ref>
      <ref url="http://milw0rm.com/exploits/4849" source="MILW0RM">4849</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39445" source="XF">loudblog-template-code-execution(39445)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="loudblog" name="loudblog">
        <vers prev="1" num="0.8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0140" published="2008-01-08" name="CVE-2008-0140" modified="2008-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in error.php in Uebimiau Webmail 2.7.10 and 2.7.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the selected_theme parameter, a different vector than CVE-2007-3172.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39460" source="XF">uebimiau-webmail-error-directory-traversal(39460)</ref>
      <ref url="http://www.securityfocus.com/bid/27154" source="BID">27154</ref>
      <ref url="http://www.milw0rm.com/exploits/4846" source="MILW0RM">4846</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2008-January/001867.html" source="VIM">20080107 Uebimiau Web-Mail 2.7.10/2.7.2 Remote File Disclosure Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uebimiau" name="webmail">
        <vers num="2.7.10"/>
        <vers num="2.7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0141" published="2008-01-08" name="CVE-2008-0141" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">actions.php in WebPortal CMS 0.6-beta generates predictable passwords containing only the time of day, which makes it easier for remote attackers to obtain access to any account via a lostpass action.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27145" source="BID">27145</ref>
      <ref url="http://www.milw0rm.com/exploits/4835" source="MILW0RM">4835</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39486" source="XF">webportal-action-weak-security(39486)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webportal" name="webportal_cms">
        <vers num="0.6_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0142" published="2008-01-08" name="CVE-2008-0142" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in WebPortal CMS 0.6-beta allow remote attackers to execute arbitrary SQL commands via the user_name parameter to actions.php, and unspecified other vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/4835" source="MILW0RM">4835</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webportal" name="webportal_cms">
        <vers num="0.6_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0143" published="2008-01-08" name="CVE-2008-0143" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in common/db.php in samPHPweb, possibly 4.2.2 and others, as provided with SAM Broadcaster, allows remote attackers to execute arbitrary PHP code via a URL in the commonpath parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39397" source="XF">samPHPweb-db-file-include(39397)</ref>
      <ref url="http://www.spacialaudio.com/news/index.html" source="CONFIRM">http://www.spacialaudio.com/news/index.html</ref>
      <ref url="http://www.securityfocus.com/bid/27137" source="BID">27137</ref>
      <ref url="http://www.milw0rm.com/exploits/4834" source="MILW0RM">4834</ref>
      <ref url="http://secunia.com/advisories/28355" source="SECUNIA" adv="1">28355</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spacial_audio_solutions" name="sam_broadcaster">
        <vers num=""/>
      </prod>
      <prod vendor="spacial_audio_solutions" name="samphpweb">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0144" published="2008-01-08" name="CVE-2008-0144" modified="2009-09-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in NetRisk 1.9.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.  NOTE: this can also be leveraged for local file inclusion using directory traversal sequences.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39419" source="XF">netrisk-index-file-include(39419)</ref>
      <ref url="http://www.securityfocus.com/bid/27136" source="BID">27136</ref>
      <ref url="http://www.milw0rm.com/exploits/4833" source="MILW0RM">4833</ref>
      <ref url="http://secunia.com/advisories/28328" source="SECUNIA">28328</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=119955114428283&amp;w=2" source="BUGTRAQ">20080105 NetRisk 1.9.7 Remote File Inclusion Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phprisk" name="netrisk">
        <vers num="1.9.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0145" published="2008-01-08" name="CVE-2008-0145" modified="2009-09-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in glob in PHP before 4.4.8, when open_basedir is enabled, has unknown impact and attack vectors.  NOTE: this issue reportedly exists because of a regression related to CVE-2007-4663.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39401" source="XF">php-glob-openbasedir-security-bypass(39401)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0059" source="VUPEN">ADV-2008-0059</ref>
      <ref url="http://www.php.net/releases/4_4_8.php" source="CONFIRM">http://www.php.net/releases/4_4_8.php</ref>
      <ref url="http://www.php.net/ChangeLog-4.php" source="CONFIRM">http://www.php.net/ChangeLog-4.php</ref>
      <ref url="http://secunia.com/advisories/28318" source="SECUNIA">28318</ref>
      <ref url="http://bugs.php.net/bug.php?id=41655" source="CONFIRM">http://bugs.php.net/bug.php?id=41655</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2008&amp;m=slackware-security.335136" source="SLACKWARE">SSA:2008-045-03</ref>
      <ref url="http://secunia.com/advisories/28936" source="SECUNIA">28936</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers prev="1" num="4.4.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0146" published="2008-01-08" name="CVE-2008-0146" modified="2009-09-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the error page in W3-mSQL allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the top-level URI.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27116" source="BID">27116</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485736/100/0/threaded" source="BUGTRAQ">20080103 xss in w3-msql error page</ref>
      <ref url="http://secunia.com/advisories/28294" source="SECUNIA" adv="1">28294</ref>
      <ref url="http://osvdb.org/51235" source="OSVDB">51235</ref>
      <ref url="http://securityreason.com/securityalert/3521" source="SREASON">3521</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hughes_technologies" name="w3-msql">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0147" published="2008-01-08" name="CVE-2008-0147" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in SmallNuke 2.0.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via (1) the user_email parameter and possibly (2) username parameter in a Members action.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27180" source="BID">27180</ref>
      <ref url="http://www.milw0rm.com/exploits/4863" source="MILW0RM">4863</ref>
      <ref url="http://secunia.com/advisories/28301" source="SECUNIA" adv="1">28301</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39525" source="XF">smallnuke-index-sql-injection(39525)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smallnuke" name="smallnuke">
        <vers num="2.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0148" published="2008-01-08" name="CVE-2008-0148" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell commands via the cmd parameter in a direct request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/28291" source="SECUNIA" adv="1">28291</ref>
      <ref url="http://milw0rm.com/exploits/4861" source="MILW0RM">4861</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39531" source="XF">tutos-cmd-command-execution(39531)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tutos" name="tutos">
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0149" published="2008-01-08" name="CVE-2008-0149" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TUTOS 1.3 allows remote attackers to read system information via a direct request to php/admin/phpinfo.php, which calls the phpinfo function.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/28291" source="SECUNIA" adv="1">28291</ref>
      <ref url="http://milw0rm.com/exploits/4861" source="MILW0RM">4861</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tutos" name="tutos">
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0150" published="2008-01-08" name="CVE-2008-0150" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the LDAP authentication feature in Aruba Mobility Controller 2.3.6.15, 2.5.2.11, 2.5.4.25, 2.5.5.7, 3.1.1.3, and 2.4.8.11-FIPS or earlier allows remote attackers to bypass authentication mechanisms and obtain management or VPN interface access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27144" source="BID">27144</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485831/100/0/threaded" source="BUGTRAQ">20080104 Aruba Mobility Controller User Authentication Vulnerability - Aruba Advisory ID: AID-122207</ref>
      <ref url="http://www.arubanetworks.com/support/alerts/aid-122207.asc" source="CONFIRM">http://www.arubanetworks.com/support/alerts/aid-122207.asc</ref>
      <ref url="http://secunia.com/advisories/28357" source="SECUNIA" adv="1">28357</ref>
      <ref url="http://securityreason.com/securityalert/3529" source="SREASON">3529</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aruba_networks" name="aruba_mobility_controllers">
        <vers num="2.3.6.15"/>
        <vers prev="1" num="2.4.8.11-fips"/>
        <vers num="2.5.2.11"/>
        <vers num="2.5.4.25"/>
        <vers num="2.5.5.7"/>
        <vers num="3.1.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0151" published="2008-01-08" name="CVE-2008-0151" modified="2009-08-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Foxit WAC Server 2.1.0.910, 2.0 Build 3503, and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Telnet request with long options.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39427" source="XF">wacserver-option-dos(39427)</ref>
      <ref url="http://www.securityfocus.com/bid/27142" source="BID">27142</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488366/100/200/threaded" source="BUGTRAQ">20080219 Two heap overflow in Foxit WAC Server 2.0 Build 3503</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485812/100/0/threaded" source="BUGTRAQ">20080104 Some DoS in some telnet servers</ref>
      <ref url="http://securityreason.com/securityalert/3525" source="SREASON">3525</ref>
      <ref url="http://secunia.com/advisories/28272" source="SECUNIA" adv="1">28272</ref>
      <ref url="http://aluigi.altervista.org/adv/wachof-adv.txt" source="MISC">http://aluigi.altervista.org/adv/wachof-adv.txt</ref>
      <ref url="http://aluigi.altervista.org/adv/waccaz-adv.txt" source="MISC">http://aluigi.altervista.org/adv/waccaz-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="foxitsoftware" name="wac_server">
        <vers num="2.0"/>
        <vers num="2.1.0.910"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0152" published="2008-01-08" name="CVE-2008-0152" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">SLnet.exe in SeattleLab SLNet RF Telnet Server 4.1.1.3758 and earlier allows user-assisted remote attackers to cause a denial of service (crash) via unspecified telnet options, which triggers a NULL pointer dereference.  NOTE: the crash is not user-assisted when the server is running in debug mode.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27134" source="BID">27134</ref>
      <ref url="http://secunia.com/advisories/28316" source="SECUNIA" adv="1">28316</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=119947184730448&amp;w=2" source="BUGTRAQ">20080104 Some DoS in some telnet servers</ref>
      <ref url="http://aluigi.altervista.org/adv/slnetmsg-adv.txt" source="MISC">http://aluigi.altervista.org/adv/slnetmsg-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="seattle_lab_software" name="slnet_rf_telnet_server">
        <vers prev="1" num="4.1.1.3758"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0153" published="2008-01-08" name="CVE-2008-0153" modified="2008-10-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">telnetd.exe in Pragma TelnetServer 7.0.4.589 allows remote attackers to cause a denial of service (process crash and resource exhaustion) via a crafted TELOPT PRAGMA LOGON telnet option, which triggers a NULL pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39353" source="XF">pragmatelnetserver-telnetd-dos(39353)</ref>
      <ref url="http://www.securityfocus.com/bid/27143" source="BID">27143</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=119947184730448&amp;w=2" source="BUGTRAQ">20080104 Some DoS in some telnet servers</ref>
      <ref url="http://aluigi.altervista.org/adv/pragmatel-adv.txt" source="MISC">http://aluigi.altervista.org/adv/pragmatel-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pragma_systems" name="pragma_telnetserver">
        <vers num="7.0.4.589"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0154" published="2008-01-08" name="CVE-2008-0154" modified="2009-09-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to execute arbitrary SQL commands the c parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39529" source="XF">evilboard-index-sql-injection(39529)</ref>
      <ref url="http://www.securityfocus.com/bid/27190" source="BID">27190</ref>
      <ref url="http://www.milw0rm.com/exploits/4865" source="MILW0RM">4865</ref>
    </refs>
    <vuln_soft>
      <prod vendor="evilboard" name="evilboard">
        <vers num="0.1a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0155" published="2008-01-08" name="CVE-2008-0155" modified="2009-09-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to inject arbitrary web script or HTML via the c parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27190" source="BID">27190</ref>
      <ref url="http://www.milw0rm.com/exploits/4865" source="MILW0RM">4865</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39526" source="XF">evilboard-index-xss(39526)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="evilboard" name="evilboard">
        <vers num="0.1a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0156" published="2008-01-08" name="CVE-2008-0156" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Absolute path traversal vulnerability in index.php in Million Dollar Script 2.0.14 allows remote attackers to read arbitrary files via encoded "/" (%2F) sequences in the link parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39492" source="XF">milliondollarscript-index-dir-traversal(39492)</ref>
      <ref url="http://www.securityfocus.com/bid/27174" source="BID">27174</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485882/100/0/threaded" source="BUGTRAQ">20080107 Million Dollar Script 2.0.14 Remote File Disclosure Vulnerability.</ref>
      <ref url="http://securityreason.com/securityalert/3524" source="SREASON">3524</ref>
    </refs>
    <vuln_soft>
      <prod vendor="million_dollar_script" name="million_dollar_script">
        <vers num="2.0.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0157" published="2008-01-08" name="CVE-2008-0157" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in FlexBB 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the flexbb_temp_id parameter in a cookie.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39475" source="XF">flexbb-flexbbtempid-sql-injection(39475)</ref>
      <ref url="http://www.securityfocus.com/bid/27164" source="BID">27164</ref>
      <ref url="http://www.milw0rm.com/exploits/4858" source="MILW0RM">4858</ref>
      <ref url="http://secunia.com/advisories/28373" source="SECUNIA">28373</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flexbb" name="flexbb">
        <vers prev="1" num="0.6.3"/>
        <vers num="1.0_10005_beta_release_1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0158" published="2008-01-08" name="CVE-2008-0158" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in Shop-Script 2.0 and possibly other versions allows remote attackers to read arbitrary files via a .. (dot dot) in the aux_page parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39449" source="XF">shopscript-index-directory-traversal(39449)</ref>
      <ref url="http://www.securityfocus.com/bid/27165" source="BID">27165</ref>
      <ref url="http://packetstormsecurity.org/0801-exploits/shopscript-disclose.txt" source="MISC">http://packetstormsecurity.org/0801-exploits/shopscript-disclose.txt</ref>
      <ref url="http://www.milw0rm.com/exploits/4855" source="MILW0RM">4855</ref>
    </refs>
    <vuln_soft>
      <prod vendor="shop-script" name="shop-script">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0159" published="2008-01-08" name="CVE-2008-0159" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in eggBlog 3.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the eggblogpassword parameter in a cookie.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39473" source="XF">eggblog-eggblogmail-sql-injection(39473)</ref>
      <ref url="http://www.securityfocus.com/bid/27168" source="BID">27168</ref>
      <ref url="http://www.milw0rm.com/exploits/4860" source="MILW0RM">4860</ref>
      <ref url="http://secunia.com/advisories/28371" source="SECUNIA">28371</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eggblog" name="eggblog">
        <vers prev="1" num="3.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0162" published="2008-02-22" name="CVE-2008-0162" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">misc.c in splitvt 1.6.6 and earlier does not drop group privileges before executing xprop, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2008/dsa-1500" source="DEBIAN" patch="1">DSA-1500</ref>
      <ref url="http://www.securityfocus.com/bid/27936" source="BID">27936</ref>
      <ref url="http://secunia.com/advisories/29080" source="SECUNIA" adv="1">29080</ref>
      <ref url="http://secunia.com/advisories/29064" source="SECUNIA" adv="1">29064</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200803-05.xml" source="GENTOO">GLSA-200803-05</ref>
      <ref url="http://secunia.com/advisories/29190" source="SECUNIA">29190</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sam_lantinga" name="splitvt">
        <vers prev="1" num="1.6.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0163" published="2008-02-12" name="CVE-2008-0163" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Linux kernel 2.6, when using vservers, allows local users to access resources of other vservers via a symlink attack in /proc.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2008/dsa-1494" source="DEBIAN" patch="1">DSA-1494</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40486" source="XF">linux-kernel-proc-unauth-access(40486)</ref>
      <ref url="http://www.securityfocus.com/bid/27798" source="BID">27798</ref>
      <ref url="http://www.securityfocus.com/bid/27704" source="BID">27704</ref>
      <ref url="http://secunia.com/advisories/28875" source="SECUNIA">28875</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0164" published="2008-03-19" name="CVE-2008-0164" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in Plone CMS 3.0.5 and 3.0.6 allow remote attackers to (1) add arbitrary accounts via the join_form page and (2) change the privileges of arbitrary groups via the prefs_groups_overview page.</descript>
      <descript source="nvd">Must login to view link 1015140</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/489544/100/0/threaded" source="BUGTRAQ">20080313 PR08-02: Plone CMS Security Research - the Art of Plowning</ref>
      <ref url="http://www.procheckup.com/Hacking_Plone_CMS.pdf" source="MISC">http://www.procheckup.com/Hacking_Plone_CMS.pdf</ref>
      <ref url="http://secunia.com/advisories/29361" source="SECUNIA" adv="1">29361</ref>
      <ref url="http://plone.org/about/security/advisories/cve-2008-0164" source="MISC">http://plone.org/about/security/advisories/cve-2008-0164</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41263" source="XF">plone-joinform-csrf(41263)</ref>
      <ref url="http://securityreason.com/securityalert/3754" source="SREASON">3754</ref>
    </refs>
    <vuln_soft>
      <prod vendor="plone" name="plone_cms">
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0165" published="2008-04-21" name="CVE-2008-0165" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in Ikiwiki before 2.42 allows remote attackers to modify user preferences, including passwords, via the (1) preferences and (2) edit forms.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/41904" source="XF">ikiwiki-change-password-csrf(41904)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1297/references" source="VUPEN">ADV-2008-1297</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1553" source="DEBIAN">DSA-1553</ref>
      <ref url="http://secunia.com/advisories/29932" source="SECUNIA">29932</ref>
      <ref url="http://secunia.com/advisories/29907" source="SECUNIA">29907</ref>
      <ref url="http://ikiwiki.info/security/#index31h2" source="CONFIRM">http://ikiwiki.info/security/#index31h2</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=475445" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=475445</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ikiwiki" name="ikiwiki">
        <vers prev="1" num="2.41"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0166" published="2008-05-13" name="CVE-2008-0166" modified="2009-02-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptographic keys.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-137A.html" source="CERT">TA08-137A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/925211" source="CERT-VN">VU#925211</ref>
      <ref url="http://www.ubuntu.com/usn/usn-612-2" source="UBUNTU" patch="1">USN-612-2</ref>
      <ref url="http://www.ubuntu.com/usn/usn-612-1" source="UBUNTU" patch="1">USN-612-1</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1576" source="DEBIAN" patch="1">DSA-1576</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1571" source="DEBIAN" patch="1" adv="1">DSA-1571</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/42375" source="XF">openssl-rng-weak-security(42375)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-612-7" source="UBUNTU">USN-612-7</ref>
      <ref url="http://www.ubuntu.com/usn/usn-612-4" source="UBUNTU">USN-612-4</ref>
      <ref url="http://www.ubuntu.com/usn/usn-612-3" source="UBUNTU">USN-612-3</ref>
      <ref url="http://www.securitytracker.com/id?1020017" source="SECTRACK">1020017</ref>
      <ref url="http://www.securityfocus.com/bid/29179" source="BID">29179</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/492112/100/0/threaded" source="BUGTRAQ">20080515 Debian generated SSH-Keys working exploit</ref>
      <ref url="http://www.milw0rm.com/exploits/5720" source="MILW0RM">5720</ref>
      <ref url="http://www.milw0rm.com/exploits/5632" source="MILW0RM">5632</ref>
      <ref url="http://www.milw0rm.com/exploits/5622" source="MILW0RM">5622</ref>
      <ref url="http://sourceforge.net/mailarchive/forum.php?thread_name=48367252.7070603%40shemesh.biz&amp;forum_name=rsyncrypto-devel" source="MLIST">[rsyncrypto-devel] 20080523 Advisory - Rsyncrypto maybe affected from Debian OpenSSL reduced entropy problem</ref>
      <ref url="http://secunia.com/advisories/30249" source="SECUNIA" adv="1">30249</ref>
      <ref url="http://secunia.com/advisories/30239" source="SECUNIA" adv="1">30239</ref>
      <ref url="http://secunia.com/advisories/30231" source="SECUNIA" adv="1">30231</ref>
      <ref url="http://secunia.com/advisories/30221" source="SECUNIA" adv="1">30221</ref>
      <ref url="http://secunia.com/advisories/30220" source="SECUNIA" adv="1">30220</ref>
      <ref url="http://secunia.com/advisories/30136" source="SECUNIA" adv="1">30136</ref>
      <ref url="http://metasploit.com/users/hdm/tools/debian-openssl/" source="MISC">http://metasploit.com/users/hdm/tools/debian-openssl/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl_project" name="openssl">
        <vers num="0.9.8c-1"/>
        <vers num="0.9.8c-2"/>
        <vers num="0.9.8c-3"/>
        <vers num="0.9.8c-4"/>
        <vers num="0.9.8c-5"/>
        <vers num="0.9.8c-6"/>
        <vers num="0.9.8c-7"/>
        <vers num="0.9.8c-8"/>
        <vers num="0.9.8c-9"/>
        <vers num="0.9.8d-1"/>
        <vers num="0.9.8d-2"/>
        <vers num="0.9.8d-3"/>
        <vers num="0.9.8d-4"/>
        <vers num="0.9.8d-5"/>
        <vers num="0.9.8d-6"/>
        <vers num="0.9.8d-7"/>
        <vers num="0.9.8d-8"/>
        <vers num="0.9.8d-9"/>
        <vers num="0.9.8e-1"/>
        <vers num="0.9.8e-2"/>
        <vers num="0.9.8e-3"/>
        <vers num="0.9.8e-4"/>
        <vers num="0.9.8e-5"/>
        <vers num="0.9.8e-6"/>
        <vers num="0.9.8e-7"/>
        <vers num="0.9.8e-8"/>
        <vers num="0.9.8e-9"/>
        <vers num="0.9.8f-1"/>
        <vers num="0.9.8f-2"/>
        <vers num="0.9.8f-3"/>
        <vers num="0.9.8f-4"/>
        <vers num="0.9.8f-5"/>
        <vers num="0.9.8f-6"/>
        <vers num="0.9.8f-7"/>
        <vers num="0.9.8f-8"/>
        <vers num="0.9.8f-9"/>
        <vers num="0.9.8g-1"/>
        <vers num="0.9.8g-2"/>
        <vers num="0.9.8g-3"/>
        <vers num="0.9.8g-4"/>
        <vers num="0.9.8g-5"/>
        <vers num="0.9.8g-6"/>
        <vers num="0.9.8g-7"/>
        <vers num="0.9.8g-8"/>
        <vers num="0.9.8g-9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0167" published="2008-05-18" name="CVE-2008-0167" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictions or have unspecified other impact in opportunistic circumstances.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2008/dsa-1577" source="DEBIAN" patch="1">DSA-1577</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/42456" source="XF">gforge-unspecified-symlink(42456)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1537/references" source="VUPEN">ADV-2008-1537</ref>
      <ref url="http://www.securityfocus.com/bid/29215" source="BID">29215</ref>
      <ref url="http://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14-22etch8.diff.gz" source="CONFIRM">http://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14-22etch8.diff.gz</ref>
      <ref url="http://secunia.com/advisories/30286" source="SECUNIA" adv="1">30286</ref>
      <ref url="http://secunia.com/advisories/30088" source="SECUNIA" adv="1">30088</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gforge" name="gforge">
        <vers num="4.5.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0169" published="2008-06-03" name="CVE-2008-0169" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Plugin/passwordauth.pm (aka the passwordauth plugin) in ikiwiki 1.34 through 2.47 allows remote attackers to bypass authentication, and login to any account for which an OpenID identity is configured and a password is not configured, by specifying an empty password during the login sequence.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/42798" source="XF">ikiwiki-openid-passwordauth-auth-bypass(42798)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1710" source="VUPEN">ADV-2008-1710</ref>
      <ref url="http://www.securityfocus.com/bid/29479" source="BID">29479</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2008/05/31/3" source="MLIST">[oss-security] 20080531 Re: CVE id request: ikiwiki</ref>
      <ref url="http://secunia.com/advisories/30468" source="SECUNIA" adv="1">30468</ref>
      <ref url="http://ikiwiki.info/security/#index33h2" source="CONFIRM">http://ikiwiki.info/security/#index33h2</ref>
      <ref url="http://ikiwiki.info/news/version_2.48/index.html" source="CONFIRM">http://ikiwiki.info/news/version_2.48/index.html</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=483770" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=483770</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ikiwiki" name="ikiwiki">
        <vers num="1.34"/>
        <vers num="1.34.1"/>
        <vers num="1.34.2"/>
        <vers num="1.35"/>
        <vers num="1.36"/>
        <vers num="1.37"/>
        <vers num="1.38"/>
        <vers num="1.39"/>
        <vers num="1.40"/>
        <vers num="1.41"/>
        <vers num="1.42"/>
        <vers num="1.43"/>
        <vers num="1.44"/>
        <vers num="1.45"/>
        <vers num="1.46"/>
        <vers num="1.47"/>
        <vers num="1.48"/>
        <vers num="1.49"/>
        <vers num="1.5"/>
        <vers num="1.51"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.10"/>
        <vers num="2.11"/>
        <vers num="2.12"/>
        <vers num="2.13"/>
        <vers num="2.14"/>
        <vers num="2.15"/>
        <vers num="2.16"/>
        <vers num="2.17"/>
        <vers num="2.18"/>
        <vers num="2.19"/>
        <vers num="2.2"/>
        <vers num="2.20"/>
        <vers num="2.3"/>
        <vers num="2.30"/>
        <vers num="2.31"/>
        <vers num="2.31.1"/>
        <vers num="2.31.2"/>
        <vers num="2.31.3"/>
        <vers num="2.4"/>
        <vers num="2.40"/>
        <vers num="2.41"/>
        <vers num="2.42"/>
        <vers num="2.43"/>
        <vers num="2.44"/>
        <vers num="2.47"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.7"/>
        <vers num="2.8"/>
        <vers num="2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0171" published="2008-01-17" name="CVE-2008-0171" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">regex/v4/perl_matcher_non_recursive.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (failed assertion and crash) via an invalid regular expression.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://issues.rpath.com/browse/RPL-2143" source="CONFIRM">https://issues.rpath.com/browse/RPL-2143</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0249" source="VUPEN">ADV-2008-0249</ref>
      <ref url="http://www.ubuntu.com/usn/usn-570-1" source="UBUNTU">USN-570-1</ref>
      <ref url="http://www.securityfocus.com/bid/27325" source="BID">27325</ref>
      <ref url="http://svn.boost.org/trac/boost/changeset/42745" source="CONFIRM">http://svn.boost.org/trac/boost/changeset/42745</ref>
      <ref url="http://svn.boost.org/trac/boost/changeset/42674" source="CONFIRM">http://svn.boost.org/trac/boost/changeset/42674</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=205955" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=205955</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00760.html" source="FEDORA">FEDORA-2008-0880</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488102/100/0/threaded" source="BUGTRAQ">20080213 rPSA-2008-0063-1 boost</ref>
      <ref url="http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:032" source="MANDRIVA">MDVSA-2008:032</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200802-08.xml" source="GENTOO">GLSA-200802-08</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2008-0063" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2008-0063</ref>
      <ref url="http://secunia.com/advisories/29323" source="SECUNIA">29323</ref>
      <ref url="http://secunia.com/advisories/28943" source="SECUNIA">28943</ref>
      <ref url="http://secunia.com/advisories/28860" source="SECUNIA">28860</ref>
      <ref url="http://secunia.com/advisories/28705" source="SECUNIA">28705</ref>
      <ref url="http://secunia.com/advisories/28545" source="SECUNIA">28545</ref>
      <ref url="http://secunia.com/advisories/28527" source="SECUNIA">28527</ref>
      <ref url="http://secunia.com/advisories/28511" source="SECUNIA">28511</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html" source="SUSE">SUSE-SR:2008:006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="boost" name="boost">
        <vers num="1.33"/>
        <vers num="1.34"/>
      </prod>
      <prod vendor="boost" name="boost_regex_library">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0172" published="2008-01-17" name="CVE-2008-0172" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The get_repeat_type function in basic_regex_creator.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (NULL dereference and crash) via an invalid regular expression.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://issues.rpath.com/browse/RPL-2143" source="CONFIRM">https://issues.rpath.com/browse/RPL-2143</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0249" source="VUPEN">ADV-2008-0249</ref>
      <ref url="http://www.ubuntu.com/usn/usn-570-1" source="UBUNTU">USN-570-1</ref>
      <ref url="http://www.securityfocus.com/bid/27325" source="BID">27325</ref>
      <ref url="http://svn.boost.org/trac/boost/changeset/42745" source="CONFIRM">http://svn.boost.org/trac/boost/changeset/42745</ref>
      <ref url="http://svn.boost.org/trac/boost/changeset/42674" source="CONFIRM">http://svn.boost.org/trac/boost/changeset/42674</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=205955" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=205955</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00760.html" source="FEDORA">FEDORA-2008-0880</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488102/100/0/threaded" source="BUGTRAQ">20080213 rPSA-2008-0063-1 boost</ref>
      <ref url="http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:032" source="MANDRIVA">MDVSA-2008:032</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200802-08.xml" source="GENTOO">GLSA-200802-08</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2008-0063" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2008-0063</ref>
      <ref url="http://secunia.com/advisories/29323" source="SECUNIA">29323</ref>
      <ref url="http://secunia.com/advisories/28943" source="SECUNIA">28943</ref>
      <ref url="http://secunia.com/advisories/28860" source="SECUNIA">28860</ref>
      <ref url="http://secunia.com/advisories/28705" source="SECUNIA">28705</ref>
      <ref url="http://secunia.com/advisories/28545" source="SECUNIA">28545</ref>
      <ref url="http://secunia.com/advisories/28527" source="SECUNIA">28527</ref>
      <ref url="http://secunia.com/advisories/28511" source="SECUNIA">28511</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html" source="SUSE">SUSE-SR:2008:006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="boost" name="boost">
        <vers num="1.33"/>
        <vers num="1.34"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0173" published="2008-01-15" name="CVE-2008-0173" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2008/dsa-1459" source="DEBIAN" patch="1">DSA-1459</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0115" source="VUPEN">ADV-2008-0115</ref>
      <ref url="http://www.securityfocus.com/bid/27266" source="BID">27266</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39666" source="XF">gforge-multiple-sql-injection(39666)</ref>
      <ref url="http://secunia.com/advisories/28451" source="SECUNIA">28451</ref>
      <ref url="http://secunia.com/advisories/28395" source="SECUNIA">28395</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gforge" name="gforge">
        <vers prev="1" num="4.6.99"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0174" published="2008-01-28" name="CVE-2008-0174" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the passwords and gain privileges.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/180876" source="CERT-VN">VU#180876</ref>
      <ref url="http://www.securityfocus.com/bid/30754" source="BID">30754</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487075/100/0/threaded" source="BUGTRAQ">20080125 C4 Security Advisory - GE Fanuc Proficy Information Portal 2.6 Authentication Vulnerability</ref>
      <ref url="http://support.gefanuc.com/support/index?page=kbchannel&amp;id=KB12459" source="CONFIRM">http://support.gefanuc.com/support/index?page=kbchannel&amp;id=KB12459</ref>
      <ref url="http://securitytracker.com/id?1019273" source="SECTRACK">1019273</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487244/100/0/threaded" source="BUGTRAQ">20080129 Re: C4 Security Advisory - GE Fanuc Proficy Information Portal 2.6 Authentication Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/3590" source="SREASON">3590</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ge_fanuc" name="proficy_real-time_information_portal">
        <vers prev="1" num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0175" published="2008-01-28" name="CVE-2008-0175" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension to the main virtual directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/339345" source="CERT-VN">VU#339345</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0307/references" source="VUPEN">ADV-2008-0307</ref>
      <ref url="http://www.securitytracker.com/id?1019274" source="SECTRACK">1019274</ref>
      <ref url="http://www.securityfocus.com/bid/27446" source="BID">27446</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487079/100/0/threaded" source="BUGTRAQ">20080125 C4 Security Advisory - GE Fanuc Proficy Information Portal 2.6 Arbitrary File Upload and Execution</ref>
      <ref url="http://support.gefanuc.com/support/index?page=kbchannel&amp;id=KB12460" source="CONFIRM">http://support.gefanuc.com/support/index?page=kbchannel&amp;id=KB12460</ref>
      <ref url="http://secunia.com/advisories/28678" source="SECUNIA" adv="1">28678</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487242/100/0/threaded" source="BUGTRAQ">20080129 Re: C4 Security Advisory - GE Fanuc Proficy Information Portal 2.6 Arbitrary File Upload and Execution</ref>
      <ref url="http://securityreason.com/securityalert/3591" source="SREASON">3591</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ge_fanuc" name="proficy_real-time_information_portal">
        <vers prev="1" num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0176" published="2008-01-28" name="CVE-2008-0176" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in w32rtr.exe in GE Fanuc CIMPLICITY HMI SCADA system 7.0 before 7.0 SIM 9, and earlier versions before 6.1 SP6 Hot fix - 010708_162517_6106, allow remote attackers to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/308556" source="CERT-VN">VU#308556</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0306" source="VUPEN">ADV-2008-0306</ref>
      <ref url="http://www.securitytracker.com/id?1019275" source="SECTRACK">1019275</ref>
      <ref url="http://www.securityfocus.com/bid/27447" source="BID">27447</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487076/100/0/threaded" source="BUGTRAQ">20080125 C4 Security Advisory - GE Fanuc Cimplicity 6.1 Heap Overflow</ref>
      <ref url="http://support.gefanuc.com/support/index?page=kbchannel&amp;id=KB12458" source="CONFIRM">http://support.gefanuc.com/support/index?page=kbchannel&amp;id=KB12458</ref>
      <ref url="http://secunia.com/advisories/28663" source="SECUNIA" adv="1">28663</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487241/100/0/threaded" source="BUGTRAQ">20080129 Re: C4 Security Advisory - GE Fanuc Cimplicity 6.1 Heap Overflow</ref>
      <ref url="http://securityreason.com/securityalert/3592" source="SREASON">3592</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ge_fanuc" name="cimplicity">
        <vers prev="1" num="6.1_sp6_hf_010708_162517_6106"/>
        <vers prev="1" num="7.0_sim8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0177" published="2008-02-07" name="CVE-2008-0177" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The ipcomp6_input function in sys/netinet6/ipcomp_input.c in the KAME project before 20071201 does not properly check the return value of the m_pulldown function, which allows remote attackers to cause a denial of service (system crash) via an IPv6 packet with an IPComp header.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/110947" source="CERT-VN">VU#110947</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-150A.html" source="CERT">TA08-150A</ref>
      <ref url="http://www.securityfocus.com/bid/27642" source="BID" patch="1">27642</ref>
      <ref url="http://secunia.com/advisories/28788" source="SECUNIA" patch="1" adv="1">28788</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/2094/references" source="VUPEN">ADV-2008-2094</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1697" source="VUPEN">ADV-2008-1697</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0688" source="VUPEN">ADV-2008-0688</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0441" source="VUPEN">ADV-2008-0441</ref>
      <ref url="http://www.kame.net/dev/cvsweb2.cgi/kame/kame/sys/netinet6/ipcomp_input.c.diff?r1=1.36;r2=1.37" source="CONFIRM">http://www.kame.net/dev/cvsweb2.cgi/kame/kame/sys/netinet6/ipcomp_input.c.diff?r1=1.36;r2=1.37</ref>
      <ref url="http://secunia.com/advisories/31074" source="SECUNIA">31074</ref>
      <ref url="http://secunia.com/advisories/28816" source="SECUNIA" adv="1">28816</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008//Jul/msg00001.html" source="APPLE">APPLE-SA-2008-07-11</ref>
      <ref url="http://cvsweb.netbsd.org/bsdweb.cgi/src/sys/netinet6/ipcomp_input.c?f=u&amp;only_with_tag=netbsd-3-1" source="CONFIRM" adv="1">http://cvsweb.netbsd.org/bsdweb.cgi/src/sys/netinet6/ipcomp_input.c?f=u&amp;only_with_tag=netbsd-3-1</ref>
      <ref url="http://www.milw0rm.com/exploits/5191" source="MILW0RM">5191</ref>
      <ref url="http://securitytracker.com/id?1019314" source="SECTRACK">1019314</ref>
      <ref url="http://security.freebsd.org/advisories/FreeBSD-SA-08:04.ipsec.asc" source="FREEBSD">FreeBSD-SA-08:04</ref>
      <ref url="http://secunia.com/advisories/30430" source="SECUNIA">30430</ref>
      <ref url="http://secunia.com/advisories/29130" source="SECUNIA">29130</ref>
      <ref url="http://secunia.com/advisories/28979" source="SECUNIA">28979</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008//May/msg00001.html" source="APPLE">APPLE-SA-2008-05-28</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kame" name="ipcomp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0178" published="2008-02-04" name="CVE-2008-0178" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Enterprise Admin Session Monitoring component in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the User-Agent HTTP header.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/326065" source="CERT-VN">VU#326065</ref>
      <ref url="http://www.securityfocus.com/bid/27547" source="BID" patch="1">27547</ref>
      <ref url="http://support.liferay.com/browse/LEP-4736" source="CONFIRM">http://support.liferay.com/browse/LEP-4736</ref>
      <ref url="http://secunia.com/advisories/28742" source="SECUNIA" adv="1">28742</ref>
    </refs>
    <vuln_soft>
      <prod vendor="liferay" name="liferay_enterprise_portal">
        <vers num="4.3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2008-0179" published="2008-02-04" name="CVE-2008-0179" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in service/impl/UserLocalServiceImpl.java in Liferay Portal 4.3.6 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header, which is used when composing Forgot Password e-mail messages in HTML format.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/888209" source="CERT-VN">VU#888209</ref>
      <ref url="http://www.securityfocus.com/bid/27550" source="BID" patch="1">27550</ref>
      <ref url="http://support.liferay.com/browse/LEP-4737" source="CONFIRM">http://support.liferay.com/browse/LEP-4737</ref>
      <ref url="http://secunia.com/advisories/28742" source="SECUNIA">28742</ref>
    </refs>
    <vuln_soft>
      <prod vendor="liferay" name="liferay_enterprise_portal">
        <vers num="4.3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0180" published="2008-02-04" name="CVE-2008-0180" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in themes/_unstyled/templates/init.vm in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the Greeting field in a User Profile.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/732449" source="CERT-VN">VU#732449</ref>
      <ref url="http://www.securityfocus.com/bid/27546" source="BID">27546</ref>
      <ref url="http://support.liferay.com/browse/LEP-4738" source="CONFIRM">http://support.liferay.com/browse/LEP-4738</ref>
      <ref url="http://secunia.com/advisories/28742" source="SECUNIA" adv="1">28742</ref>
    </refs>
    <vuln_soft>
      <prod vendor="liferay" name="liferay_enterprise_portal">
        <vers num="1.0"/>
        <vers num="2.0"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.2.0"/>
        <vers num="3.6.1"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.3"/>
        <vers num="4.3.1"/>
        <vers num="4.3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0181" published="2008-02-04" name="CVE-2008-0181" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Admin portlet in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the Shutdown message.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/217825" source="CERT-VN">VU#217825</ref>
      <ref url="http://www.securityfocus.com/bid/27554" source="BID" patch="1">27554</ref>
      <ref url="http://support.liferay.com/browse/LEP-4739" source="CONFIRM">http://support.liferay.com/browse/LEP-4739</ref>
      <ref url="http://secunia.com/advisories/28742" source="SECUNIA" adv="1">28742</ref>
    </refs>
    <vuln_soft>
      <prod vendor="liferay" name="liferay_enterprise_portal">
        <vers num="4.3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0182" published="2008-02-04" name="CVE-2008-0182" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in the Admin portlet in Liferay Portal before 4.4.0 allows remote authenticated users to perform unspecified actions as unspecified other authenticated users via the Shutdown message.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/767825" source="CERT-VN">VU#767825</ref>
      <ref url="http://support.liferay.com/browse/LEP-4739" source="CONFIRM">http://support.liferay.com/browse/LEP-4739</ref>
      <ref url="http://secunia.com/advisories/28742" source="SECUNIA" adv="1">28742</ref>
    </refs>
    <vuln_soft>
      <prod vendor="liferay" name="liferay_enterprise_portal">
        <vers prev="1" num="4.3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0184" published="2008-01-09" name="CVE-2008-0184" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Absolute path traversal vulnerability in index.php in Sys-Hotel on Line System allows remote attackers to read arbitrary files via an encoded "/" ("%2F") in the file parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27184" source="BID">27184</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485940/100/0/threaded" source="BUGTRAQ">20080108 sysHotel On Line Remote File Disclosure Vulnerability.</ref>
      <ref url="http://securityreason.com/securityalert/3528" source="SREASON">3528</ref>
    </refs>
    <vuln_soft>
      <prod vendor="prenotazioni_on_line" name="syshotel_on_line_system">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0185" published="2008-01-09" name="CVE-2008-0185" modified="2009-09-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in NetRisk 1.9.7 and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via the pid parameter in a profile page (possibly profile.php).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27161" source="BID">27161</ref>
      <ref url="http://www.milw0rm.com/exploits/4852" source="MILW0RM">4852</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=551208&amp;group_id=129681" source="MISC">http://sourceforge.net/project/shownotes.php?release_id=551208&amp;group_id=129681</ref>
      <ref url="http://secunia.com/advisories/28328" source="SECUNIA" adv="1">28328</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485834/100/0/threaded" source="BUGTRAQ">20080106 netrisk 1.9.7 Multiple Remote Vulnerabilities (sql injection/xss)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netrisk" name="netrisk">
        <vers num="1.9.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0186" published="2008-01-09" name="CVE-2008-0186" modified="2009-09-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in NetRisk 1.9.7 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter, possibly related to CVE-2008-0144.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27161" source="BID">27161</ref>
      <ref url="http://www.milw0rm.com/exploits/4852" source="MILW0RM">4852</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485834/100/0/threaded" source="BUGTRAQ">20080106 netrisk 1.9.7 Multiple Remote Vulnerabilities (sql injection/xss)</ref>
      <ref url="http://secunia.com/advisories/28369" source="SECUNIA">28369</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phprisk" name="netrisk">
        <vers prev="1" num="1.9.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0187" published="2008-01-09" name="CVE-2008-0187" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in songinfo.php in SAM Broadcaster samPHPweb, possibly 4.2.2 and earlier, allows remote attackers to execute arbitrary SQL commands via the songid parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39463" source="XF">sambroadcaster-songinfo-sql-injection(39463)</ref>
      <ref url="http://www.securityfocus.com/bid/27147" source="BID">27147</ref>
      <ref url="http://www.milw0rm.com/exploits/4836" source="MILW0RM">4836</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spacial_audio_solutions" name="samphpweb">
        <vers num="4.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2008-0188" reject="1" published="2008-01-16" name="CVE-2008-0188" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its requester.  Further investigation showed that it was not a new security issue.  Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" seq="2008-0189" reject="1" published="2008-01-16" name="CVE-2008-0189" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its requester.  Further investigation showed that it was not a new security issue.  Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0190" published="2008-01-09" name="CVE-2008-0190" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in templates/example_template.php in AwesomeTemplateEngine allow remote attackers to inject arbitrary web script or HTML via the (1) data[title], (2) data[message], (3) data[table][1][item], (4) data[table][1][url], or (5) data[poweredby] parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39396" source="XF">awesometemplateengine-multiple-xss(39396)</ref>
      <ref url="http://www.securityfocus.com/bid/27125" source="BID">27125</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" source="BUGTRAQ">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://websecurity.com.ua/1694/" source="MISC">http://websecurity.com.ua/1694/</ref>
      <ref url="http://securityvulns.ru/Sdocument784.html" source="MISC">http://securityvulns.ru/Sdocument784.html</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" source="FULLDISC">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://securityreason.com/securityalert/3539" source="SREASON">3539</ref>
    </refs>
    <vuln_soft>
      <prod vendor="awesometemplateengine" name="awesometemplateengine">
        <vers num="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0191" published="2008-01-09" name="CVE-2008-0191" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, which reveals the full path and the SQL database structure.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39423" source="XF">wordpress-p-path-disclosure(39423)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" source="BUGTRAQ">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://websecurity.com.ua/1634/" source="MISC">http://websecurity.com.ua/1634/</ref>
      <ref url="http://securityvulns.ru/Sdocument663.html" source="MISC">http://securityvulns.ru/Sdocument663.html</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" source="FULLDISC">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://securityreason.com/securityalert/3539" source="SREASON">3539</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="2.2"/>
        <vers num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0192" published="2008-01-09" name="CVE-2008-0192" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the popuptitle parameter to (1) wp-admin/post.php or (2) wp-admin/page-new.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39426" source="XF">wordpress-popuptitle-xss(39426)</ref>
      <ref url="http://www.securityfocus.com/bid/27123" source="BID">27123</ref>
      <ref url="http://websecurity.com.ua/1658/" source="MISC">http://websecurity.com.ua/1658/</ref>
      <ref url="http://securityvulns.ru/Sdocument714.html" source="MISC">http://securityvulns.ru/Sdocument714.html</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" source="FULLDISC">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://securityreason.com/securityalert/3539" source="SREASON">3539</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers prev="1" num="2.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0193" published="2008-01-09" name="CVE-2008-0193" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in wp-db-backup.php in WordPress 2.0.11 and earlier, and possibly 2.1.x through 2.3.x, allows remote attackers to inject arbitrary web script or HTML via the backup parameter in a wp-db-backup.php action to wp-admin/edit.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27123" source="BID">27123</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" source="BUGTRAQ">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://websecurity.com.ua/1676/" source="MISC">http://websecurity.com.ua/1676/</ref>
      <ref url="http://securityvulns.ru/Sdocument755.html" source="MISC">http://securityvulns.ru/Sdocument755.html</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" source="FULLDISC">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1502" source="DEBIAN">DSA-1502</ref>
      <ref url="http://securityreason.com/securityalert/3539" source="SREASON">3539</ref>
      <ref url="http://secunia.com/advisories/29014" source="SECUNIA">29014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers prev="1" num="2.0.11"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.3_rc1"/>
        <vers num="2.1.3_rc2"/>
        <vers num="2.2"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2_revision5002"/>
        <vers num="2.2_revision5003"/>
        <vers num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0194" published="2008-01-09" name="CVE-2008-0194" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in wp-db-backup.php in WordPress 2.0.3 and earlier allows remote attackers to read arbitrary files, delete arbitrary files, and cause a denial of service via a .. (dot dot) in the backup parameter in a wp-db-backup.php action to wp-admin/edit.php.  NOTE: this might be the same as CVE-2006-5705.1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" source="BUGTRAQ">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://websecurity.com.ua/1676/" source="MISC">http://websecurity.com.ua/1676/</ref>
      <ref url="http://securityvulns.ru/Sdocument755.html" source="MISC">http://securityvulns.ru/Sdocument755.html</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" source="FULLDISC">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1502" source="DEBIAN">DSA-1502</ref>
      <ref url="http://securityreason.com/securityalert/3539" source="SREASON">3539</ref>
      <ref url="http://secunia.com/advisories/29014" source="SECUNIA">29014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers prev="1" num="2.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0195" published="2008-01-09" name="CVE-2008-0195" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WordPress 2.0.11 and earlier allows remote attackers to obtain sensitive information via an empty value of the page parameter to certain PHP scripts under wp-admin/, which reveals the path in various error messages.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" source="BUGTRAQ">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://websecurity.com.ua/1687/" source="MISC">http://websecurity.com.ua/1687/</ref>
      <ref url="http://websecurity.com.ua/1686/" source="MISC">http://websecurity.com.ua/1686/</ref>
      <ref url="http://websecurity.com.ua/1683/" source="MISC">http://websecurity.com.ua/1683/</ref>
      <ref url="http://websecurity.com.ua/1679/" source="MISC">http://websecurity.com.ua/1679/</ref>
      <ref url="http://securityvulns.ru/Sdocument773.html" source="MISC">http://securityvulns.ru/Sdocument773.html</ref>
      <ref url="http://securityvulns.ru/Sdocument772.html" source="MISC">http://securityvulns.ru/Sdocument772.html</ref>
      <ref url="http://securityvulns.ru/Sdocument768.html" source="MISC">http://securityvulns.ru/Sdocument768.html</ref>
      <ref url="http://securityvulns.ru/Sdocument762.html" source="MISC">http://securityvulns.ru/Sdocument762.html</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" source="FULLDISC">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://securityreason.com/securityalert/3539" source="SREASON">3539</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers prev="1" num="2.0.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0196" published="2008-01-09" name="CVE-2008-0196" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in WordPress 2.0.11 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the page parameter to certain PHP scripts under wp-admin/ or (2) the import parameter to wp-admin/admin.php, as demonstrated by discovering the full path via a request for the \..\..\wp-config pathname; and allow remote attackers to modify arbitrary files via a .. (dot dot) in the file parameter to wp-admin/templates.php.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" source="BUGTRAQ">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://websecurity.com.ua/1687/" source="MISC">http://websecurity.com.ua/1687/</ref>
      <ref url="http://websecurity.com.ua/1686/" source="MISC">http://websecurity.com.ua/1686/</ref>
      <ref url="http://websecurity.com.ua/1683/" source="MISC">http://websecurity.com.ua/1683/</ref>
      <ref url="http://websecurity.com.ua/1679/" source="MISC">http://websecurity.com.ua/1679/</ref>
      <ref url="http://securityvulns.ru/Sdocument773.html" source="MISC">http://securityvulns.ru/Sdocument773.html</ref>
      <ref url="http://securityvulns.ru/Sdocument772.html" source="MISC">http://securityvulns.ru/Sdocument772.html</ref>
      <ref url="http://securityvulns.ru/Sdocument768.html" source="MISC">http://securityvulns.ru/Sdocument768.html</ref>
      <ref url="http://securityvulns.ru/Sdocument762.html" source="MISC">http://securityvulns.ru/Sdocument762.html</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" source="FULLDISC">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://securityreason.com/securityalert/3539" source="SREASON">3539</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers prev="1" num="2.0.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0197" published="2008-01-09" name="CVE-2008-0197" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in wp-contact-form/options-contactform.php in the WP-ContactForm 1.5 alpha and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) wpcf_email, (2) wpcf_subject, (3) wpcf_question, (4) wpcf_answer, (5) wpcf_success_msg, (6) wpcf_error_msg, or (7) wpcf_msg parameter to wp-admin/admin.php, or (8) the SRC attribute of an IFRAME element.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" source="BUGTRAQ">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://websecurity.com.ua/1641/" source="MISC">http://websecurity.com.ua/1641/</ref>
      <ref url="http://websecurity.com.ua/1600/" source="MISC">http://websecurity.com.ua/1600/</ref>
      <ref url="http://securityvulns.ru/Sdocument667.html" source="MISC">http://securityvulns.ru/Sdocument667.html</ref>
      <ref url="http://securityvulns.ru/Sdocument546.html" source="MISC">http://securityvulns.ru/Sdocument546.html</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" source="FULLDISC">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://securityreason.com/securityalert/3539" source="SREASON">3539</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wp-contactform">
        <vers prev="1" num="1.5_alpha"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0198" published="2008-01-09" name="CVE-2008-0198" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in wp-contact-form/options-contactform.php in the WP-ContactForm 1.5 alpha and earlier plugin for WordPress allow remote attackers to perform actions as administrators via the (1) wpcf_question, (2) wpcf_success_msg, or (3) wpcf_error_msg parameter to wp-admin/admin.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" source="BUGTRAQ">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://websecurity.com.ua/1641/" source="MISC">http://websecurity.com.ua/1641/</ref>
      <ref url="http://websecurity.com.ua/1600/" source="MISC">http://websecurity.com.ua/1600/</ref>
      <ref url="http://securityvulns.ru/Sdocument667.html" source="MISC">http://securityvulns.ru/Sdocument667.html</ref>
      <ref url="http://securityvulns.ru/Sdocument546.html" source="MISC">http://securityvulns.ru/Sdocument546.html</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" source="FULLDISC">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://securityreason.com/securityalert/3539" source="SREASON">3539</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0199" published="2008-01-09" name="CVE-2008-0199" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PRO-Search 0.17 and earlier allows remote attackers to cause a denial of service via certain values of the show_page and time parameters to the default URI.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" source="BUGTRAQ">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://websecurity.com.ua/1259/" source="MISC">http://websecurity.com.ua/1259/</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=563784&amp;group_id=149797" source="MISC">http://sourceforge.net/project/shownotes.php?release_id=563784&amp;group_id=149797</ref>
      <ref url="http://securityvulns.ru/Sdocument731.html" source="MISC">http://securityvulns.ru/Sdocument731.html</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" source="FULLDISC">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://securityreason.com/securityalert/3539" source="SREASON">3539</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pro_search" name="pro_search">
        <vers prev="1" num="0.16"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0200" published="2008-01-09" name="CVE-2008-0200" modified="2009-09-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in account/index.html in RotaBanner Local 3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) drop parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27138" source="BID">27138</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" source="BUGTRAQ">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://websecurity.com.ua/1442/" source="MISC">http://websecurity.com.ua/1442/</ref>
      <ref url="http://securityvulns.ru/Sdocument625.html" source="MISC">http://securityvulns.ru/Sdocument625.html</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" source="FULLDISC">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://securityreason.com/securityalert/3539" source="SREASON">3539</ref>
    </refs>
    <vuln_soft>
      <prod vendor="medialand" name="rotabanner_local">
        <vers prev="1" num="3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0201" published="2008-01-09" name="CVE-2008-0201" modified="2008-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39442" source="XF">expressionengine-index-xss(39442)</ref>
      <ref url="http://www.securityfocus.com/bid/27128" source="BID">27128</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" source="BUGTRAQ">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://websecurity.com.ua/1454/" source="MISC">http://websecurity.com.ua/1454/</ref>
      <ref url="http://securityvulns.ru/Sdocument472.html" source="MISC">http://securityvulns.ru/Sdocument472.html</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" source="FULLDISC">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://securityreason.com/securityalert/3539" source="SREASON">3539</ref>
    </refs>
    <vuln_soft>
      <prod vendor="expressionengine" name="expressionengine">
        <vers prev="1" num="1.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0202" published="2008-01-09" name="CVE-2008-0202" modified="2008-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">CRLF injection vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the URL parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27128" source="BID">27128</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" source="BUGTRAQ">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://websecurity.com.ua/1454/" source="MISC">http://websecurity.com.ua/1454/</ref>
      <ref url="http://securityvulns.ru/Sdocument472.html" source="MISC">http://securityvulns.ru/Sdocument472.html</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" source="FULLDISC">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://securityreason.com/securityalert/3539" source="SREASON">3539</ref>
    </refs>
    <vuln_soft>
      <prod vendor="expressionengine" name="expressionengine">
        <vers prev="1" num="1.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0203" published="2008-01-09" name="CVE-2008-0203" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in cryptographp/admin.php in the Cryptographp 1.2 and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) cryptwidth, (2) cryptheight, (3) bgimg, (4) charR, (5) charG, (6) charB, (7) charclear, (8) tfont, (9) charel, (10) charelc, (11) charelv, (12) charnbmin, (13) charnbmax, (14) charspace, (15) charsizemin, (16) charsizemax, (17) charanglemax, (18) noisepxmin, (19) noisepxmax, (20) noiselinemin, (21) noiselinemax, (22) nbcirclemin, (23) nbcirclemax, or (24) brushsize parameter to wp-admin/options-general.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" source="BUGTRAQ">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://websecurity.com.ua/1596/" source="MISC">http://websecurity.com.ua/1596/</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" source="FULLDISC">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://securityreason.com/securityalert/3539" source="SREASON">3539</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="cryptographp">
        <vers prev="1" num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0204" published="2008-01-09" name="CVE-2008-0204" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in math-comment-spam-protection.php in the Math Comment Spam Protection 2.1 and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) mcsp_opt_msg_no_answer or (2) mcsp_opt_msg_wrong_answer parameter to wp-admin/options-general.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" source="BUGTRAQ">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://websecurity.com.ua/1576/" source="MISC">http://websecurity.com.ua/1576/</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" source="FULLDISC">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://securityreason.com/securityalert/3539" source="SREASON">3539</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="math_comment_spam_protection_plugin">
        <vers prev="1" num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0205" published="2008-01-09" name="CVE-2008-0205" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in math-comment-spam-protection.php in the Math Comment Spam Protection 2.1 and earlier plugin for WordPress allow remote attackers to perform actions as administrators via the (1) mcsp_opt_msg_no_answer or (2) mcsp_opt_msg_wrong_answer parameter to wp-admin/options-general.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" source="BUGTRAQ">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://websecurity.com.ua/1576/" source="MISC">http://websecurity.com.ua/1576/</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" source="FULLDISC">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://securityreason.com/securityalert/3539" source="SREASON">3539</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="math_comment_spam_protection_plugin">
        <vers prev="1" num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0206" published="2008-01-09" name="CVE-2008-0206" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in captcha\captcha.php in the Captcha! 2.5d and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) captcha_ttffolder, (2) captcha_numchars, (3) captcha_ttfrange, or (4) captcha_secret parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" source="BUGTRAQ">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://websecurity.com.ua/1588/" source="MISC">http://websecurity.com.ua/1588/</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" source="FULLDISC">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://securityreason.com/securityalert/3539" source="SREASON">3539</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="captcha">
        <vers prev="1" num="2.5d"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0207" published="2008-01-09" name="CVE-2008-0207" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PRO-Search 0.17 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) prot, (2) host, (3) path, (4) name, (5) ext, (6) size, (7) search_days, or (8) show_page parameter to the default URI.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27126" source="BID">27126</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded" source="BUGTRAQ">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://websecurity.com.ua/1259/" source="MISC">http://websecurity.com.ua/1259/</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=563784&amp;group_id=149797" source="MISC">http://sourceforge.net/project/shownotes.php?release_id=563784&amp;group_id=149797</ref>
      <ref url="http://securityvulns.ru/Sdocument731.html" source="MISC">http://securityvulns.ru/Sdocument731.html</ref>
      <ref url="http://secunia.com/advisories/28335" source="SECUNIA" adv="1">28335</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html" source="FULLDISC">20080103 securityvulns.com russian vulnerabilities digest</ref>
      <ref url="http://securityreason.com/securityalert/3539" source="SREASON">3539</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pro_search" name="pro_search">
        <vers prev="1" num="0.17"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0208" published="2008-01-09" name="CVE-2008-0208" modified="2012-10-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in login.asp in Snitz Forums 2000 3.4.05 and earlier allows remote attackers to inject arbitrary web script or HTML via the target parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27162" source="BID">27162</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485836/100/200/threaded" source="BUGTRAQ">20080107 [HSC] Snitz Forums Multiple Vulnerabilities</ref>
      <ref url="http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt" source="MISC">http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt</ref>
      <ref url="http://secunia.com/advisories/28284" source="SECUNIA">28284</ref>
      <ref url="http://hackerscenter.com/archive/view.asp?id=28145" source="MISC">http://hackerscenter.com/archive/view.asp?id=28145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snitz_communications" name="snitz_forums_2000">
        <vers num="3.0"/>
        <vers num="3.1" edition="sr4"/>
        <vers num="3.2.03"/>
        <vers num="3.3"/>
        <vers num="3.3.01"/>
        <vers num="3.3.02"/>
        <vers num="3.3.03"/>
        <vers num="3.4.02"/>
        <vers num="3.4.03"/>
        <vers num="3.4.04"/>
        <vers prev="1" num="3.4.05"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0209" published="2008-01-09" name="CVE-2008-0209" modified="2012-10-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Open redirect vulnerability in Forums/login.asp in Snitz Forums 2000 3.4.06 and earlier allows remote attackers to redirect users to arbitrary web sites via a URL in the target parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485836/100/200/threaded" source="BUGTRAQ">20080107 [HSC] Snitz Forums Multiple Vulnerabilities</ref>
      <ref url="http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt" source="MISC">http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt</ref>
      <ref url="http://hackerscenter.com/archive/view.asp?id=28145" source="MISC">http://hackerscenter.com/archive/view.asp?id=28145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snitz_communications" name="snitz_forums_2000">
        <vers num="3.0"/>
        <vers num="3.1" edition="sr4"/>
        <vers num="3.2.03"/>
        <vers num="3.3"/>
        <vers num="3.3.01"/>
        <vers num="3.3.02"/>
        <vers num="3.3.03"/>
        <vers num="3.4.02"/>
        <vers num="3.4.03"/>
        <vers num="3.4.04"/>
        <vers num="3.4.05"/>
        <vers prev="1" num="3.4.06"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0210" published="2008-01-09" name="CVE-2008-0210" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Uebimiau Webmail 2.7.10 and 2.7.2 does not protect authentication state variables from being set through HTTP requests, which allows remote attackers to bypass authentication via a sess[auth]=1 parameter settting.  NOTE: this can be leveraged to conduct directory traversal attacks without authentication by using CVE-2008-0140.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27154" source="BID">27154</ref>
      <ref url="http://www.milw0rm.com/exploits/4846" source="MILW0RM">4846</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uebimiau" name="webmail">
        <vers num="2.7.10"/>
        <vers num="2.7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0211" published="2008-03-31" name="CVE-2008-0211" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in the BIOS F.04 through F.11 for the HP Compaq Business Notebook PC allows local users to cause a denial of service via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120672155821700&amp;w=2" source="HP" patch="1">HPSBGN02305</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41520" source="XF">compaq-businessnotebook-pcbios-dos(41520)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1042/references" source="VUPEN">ADV-2008-1042</ref>
      <ref url="http://www.securityfocus.com/bid/28494" source="BID">28494</ref>
      <ref url="http://securitytracker.com/id?1019729" source="SECTRACK">1019729</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120672155821700&amp;w=2" source="HP">SSRT080004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="compaq" name="2210_series_bios">
        <vers prev="1" num="f.04"/>
      </prod>
      <prod vendor="compaq" name="2510_series_bios">
        <vers prev="1" num="f.08"/>
      </prod>
      <prod vendor="compaq" name="2710_series_bios">
        <vers prev="1" num="f.0d"/>
      </prod>
      <prod vendor="compaq" name="6510_series_bios">
        <vers prev="1" num="f.0f"/>
      </prod>
      <prod vendor="compaq" name="6515_series_bios">
        <vers prev="1" num="f.0a"/>
      </prod>
      <prod vendor="compaq" name="6520_series_bios">
        <vers prev="1" num="f.08"/>
      </prod>
      <prod vendor="compaq" name="6710_series_bios">
        <vers prev="1" num="f.0f"/>
      </prod>
      <prod vendor="compaq" name="6715_series_bios">
        <vers prev="1" num="f.0a"/>
      </prod>
      <prod vendor="compaq" name="6720_series_bios">
        <vers prev="1" num="f.08"/>
      </prod>
      <prod vendor="compaq" name="6820_series_bios">
        <vers prev="1" num="f.08"/>
      </prod>
      <prod vendor="compaq" name="6910_series_bios">
        <vers prev="1" num="f.11"/>
      </prod>
      <prod vendor="compaq" name="8510_series_bios">
        <vers prev="1" num="f.0e"/>
      </prod>
      <prod vendor="compaq" name="8710_series_bios">
        <vers prev="1" num="f.08"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0212" published="2008-02-06" name="CVE-2008-0212" modified="2011-08-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">ovtopmd in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allows remote attackers to cause a denial of service (crash) via a crafted TCP request that triggers an out-of-bounds memory access.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27629" source="BID" patch="1">27629</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0424" source="VUPEN" adv="1">ADV-2008-0424</ref>
      <ref url="http://www.securitytracker.com/id?1019306" source="SECTRACK">1019306</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487586/100/0/threaded" source="HP">SSRT071420</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487586/100/0/threaded" source="HP">SSRT071420</ref>
      <ref url="http://secunia.com/advisories/28798" source="SECUNIA" adv="1">28798</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=652" source="IDEFENSE">20080204 Hewlett-Packard Network Node Manager Topology Manager Service DoS Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="6.41"/>
        <vers num="7.01"/>
        <vers num="7.51"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0213" published="2008-02-07" name="CVE-2008-0213" modified="2011-05-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in a certain ActiveX control for HP Virtual Rooms (HPVR) 6 and earlier allows remote attackers to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1019311" source="SECTRACK">1019311</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120231595903371&amp;w=2" source="HP">HPSBGN02310</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120231595903371&amp;w=2" source="HP">HPSBGN02310</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="virtual_rooms">
        <vers prev="1" num="6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0214" published="2008-02-07" name="CVE-2008-0214" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in HP Select Identity 4.00, 4.01, 4.11, 4.12, 4.13, and 4.20 allow remote authenticated users to gain access via unknown vectors.</descript>
    </desc>
    <sols>
      <sol source="nvd">In order to download the patch, user must login.</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120239931201443&amp;w=2" source="HP" patch="1">SSRT080013</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0472" source="VUPEN">ADV-2008-0472</ref>
      <ref url="http://www.securityfocus.com/bid/27667" source="BID">27667</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120239931201443&amp;w=2" source="HP">HPSBMA02309</ref>
      <ref url="http://www.securitytracker.com/id?1019322" source="SECTRACK">1019322</ref>
      <ref url="http://secunia.com/advisories/28844" source="SECUNIA">28844</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="select_identity">
        <vers num="4.00"/>
        <vers num="4.01"/>
        <vers num="4.10"/>
        <vers num="4.11"/>
        <vers num="4.12"/>
        <vers num="4.13"/>
        <vers num="4.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0215" published="2008-02-11" name="CVE-2008-0215" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in HP Storage Essentials Storage Resource Management (SRM) before 6.0.0 allow remote attackers to obtain unspecified access to a managed device via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0440" source="VUPEN">ADV-2008-0440</ref>
      <ref url="http://www.securitytracker.com/id?1019312" source="SECTRACK">1019312</ref>
      <ref url="http://www.securityfocus.com/bid/27643" source="BID">27643</ref>
      <ref url="http://secunia.com/advisories/28813" source="SECUNIA" adv="1">28813</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01316132" source="HP">SSRT071474</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01316132" source="HP">SSRT071474</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="storage_essentials_srm_enterprise">
        <vers prev="1" num="5.1.3"/>
      </prod>
      <prod vendor="hp" name="storage_essentials_srm_standard">
        <vers prev="1" num="5.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2008-0216" published="2008-01-15" name="CVE-2008-0216" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The ptsname function in FreeBSD 6.0 through 7.0-PRERELEASE does not properly verify that a certain portion of a device name is associated with a pty of a user who is calling the pt_chown function, which might allow local users to read data from the pty from another user.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://security.FreeBSD.org/advisories/FreeBSD-SA-08:01.pty.asc" source="FREEBSD" patch="1">FreeBSD-SA-08:01</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39667" source="XF">freebsd-ptsname-information-disclosure(39667)</ref>
      <ref url="http://www.securitytracker.com/id?1019191" source="SECTRACK">1019191</ref>
      <ref url="http://www.securityfocus.com/bid/27284" source="BID">27284</ref>
      <ref url="http://secunia.com/advisories/28498" source="SECUNIA">28498</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.0" edition="release"/>
        <vers num="6.0" edition="stable"/>
        <vers num="6.1" edition="release"/>
        <vers num="6.1" edition="release_p10"/>
        <vers num="6.1" edition="stable"/>
        <vers num="6.2" edition="stable"/>
        <vers num="6.3"/>
        <vers num="7.0" edition="current"/>
        <vers num="7.0" edition="pre-release"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0217" published="2008-01-15" name="CVE-2008-0217" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">The script program in FreeBSD 5.0 through 7.0-PRERELEASE invokes openpty, which creates a pseudo-terminal with world-readable and world-writable permissions when it is not run as root, which allows local users to read data from the terminal of the user running script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://security.FreeBSD.org/advisories/FreeBSD-SA-08:01.pty.asc" source="FREEBSD" patch="1">FreeBSD-SA-08:01</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39665" source="XF">freebsd-openpty-information-disclosure(39665)</ref>
      <ref url="http://www.securitytracker.com/id?1019191" source="SECTRACK">1019191</ref>
      <ref url="http://www.securityfocus.com/bid/27284" source="BID">27284</ref>
      <ref url="http://secunia.com/advisories/28498" source="SECUNIA">28498</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="5.0"/>
        <vers num="5.5"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="7.0" edition="pre-release"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0218" published="2008-01-10" name="CVE-2008-0218" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in admin/index.html in Merak IceWarp Mail Server allows remote attackers to inject arbitrary web script or HTML via the message parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39564" source="XF">icewarpmailserver-index-xss(39564)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0135" source="VUPEN">ADV-2008-0135</ref>
      <ref url="http://www.securityfocus.com/data/vulnerabilities/exploits/27189.html" source="MISC">http://www.securityfocus.com/data/vulnerabilities/exploits/27189.html</ref>
      <ref url="http://www.securityfocus.com/bid/27189" source="BID">27189</ref>
      <ref url="http://secunia.com/advisories/28460" source="SECUNIA">28460</ref>
    </refs>
    <vuln_soft>
      <prod vendor="merak" name="icewarp_mail_server">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0219" published="2008-01-10" name="CVE-2008-0219" modified="2008-10-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in soporte_horizontal_w.php in PHP Webquest 2.6 allows remote attackers to execute arbitrary SQL commands via the id_actividad parameter, a different vector than CVE-2007-4920.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39560" source="XF">webquest-soportehorizontalw-sql-injection(39560)</ref>
      <ref url="http://www.securityfocus.com/bid/27192" source="BID">27192</ref>
      <ref url="http://www.milw0rm.com/exploits/4867" source="MILW0RM">4867</ref>
      <ref url="http://secunia.com/advisories/26821" source="SECUNIA" adv="1">26821</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_webquest" name="php_webquest">
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0220" published="2008-01-10" name="CVE-2008-0220" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allow remote attackers to execute arbitrary code via a long string in the (1) second or (2) fourth argument to the DoWebLaunch method.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/735441" source="CERT-VN">VU#735441</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0077" source="VUPEN">ADV-2008-0077</ref>
      <ref url="http://www.securityfocus.com/bid/27193" source="BID">27193</ref>
      <ref url="http://www.milw0rm.com/exploits/4982" source="MILW0RM">4982</ref>
      <ref url="http://www.milw0rm.com/exploits/4869" source="MILW0RM">4869</ref>
      <ref url="http://secunia.com/advisories/28379" source="SECUNIA" adv="1">28379</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=119984138526735&amp;w=2" source="FULLDISC">20080109 Gateway WebLaunch ActiveX Control Insecure Method</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gateway" name="cweblaunchctl_activex_control">
        <vers num="1.0.0.1"/>
      </prod>
      <prod vendor="gateway" name="weblaunch">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0221" published="2008-01-10" name="CVE-2008-0221" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allows remote attackers to execute arbitrary programs via a ..\ (dot dot backslash) in the second argument to the DoWebLaunch method.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0077" source="VUPEN">ADV-2008-0077</ref>
      <ref url="http://www.milw0rm.com/exploits/4869" source="MILW0RM">4869</ref>
      <ref url="http://secunia.com/advisories/28379" source="SECUNIA" adv="1">28379</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=119984138526735&amp;w=2" source="FULLDISC">20080109 Gateway WebLaunch ActiveX Control Insecure Method</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gateway" name="weblaunch">
        <vers num="1.0.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0222" published="2008-01-10" name="CVE-2008-0222" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39462" source="XF">wordpress-wpfilemanager-file-upload(39462)</ref>
      <ref url="http://www.securityfocus.com/bid/27151" source="BID">27151</ref>
      <ref url="http://www.milw0rm.com/exploits/4844" source="MILW0RM">4844</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="filemanager">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0223" published="2008-01-10" name="CVE-2008-0223" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in JustSystems JSFC.DLL, as used in multiple JustSystems products such as Ichitaro, allows remote attackers to execute arbitrary code via a crafted .JTD file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39501" source="XF">justsystems-jsfc-bo(39501)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0045" source="VUPEN">ADV-2008-0045</ref>
      <ref url="http://www.securitytracker.com/id?1019168" source="SECTRACK">1019168</ref>
      <ref url="http://www.securityfocus.com/bid/27153" source="BID">27153</ref>
      <ref url="http://www.justsystems.com/jp/info/pd8001.html" source="CONFIRM">http://www.justsystems.com/jp/info/pd8001.html</ref>
      <ref url="http://www.fourteenforty.jp/research/advisory.cgi?FFRRA-20080107" source="MISC">http://www.fourteenforty.jp/research/advisory.cgi?FFRRA-20080107</ref>
      <ref url="http://secunia.com/advisories/28275" source="SECUNIA" adv="1">28275</ref>
      <ref url="http://jvn.jp/jp/JVN%2308237857/index.html" source="JVN">JVN#08237857</ref>
    </refs>
    <vuln_soft>
      <prod vendor="justsystem" name="ichitaro">
        <vers num="11.0"/>
        <vers num="12.0"/>
        <vers num="13.0"/>
        <vers num="2004"/>
        <vers num="2005"/>
        <vers num="2006"/>
        <vers num="2007"/>
        <vers num="linux"/>
      </prod>
      <prod vendor="justsystem" name="ichitaro_lite2">
        <vers num=""/>
      </prod>
      <prod vendor="justsystem" name="ichitaro_viewer">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0224" published="2008-01-10" name="CVE-2008-0224" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in the Newbb_plus 0.92 and earlier module in RunCMS 1.6.1 allows remote attackers to execute arbitrary SQL commands via the Client-Ip parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39478" source="XF">runcms-newbb-client-sql-injection(39478)</ref>
      <ref url="http://www.securityfocus.com/bid/27152" source="BID">27152</ref>
      <ref url="http://secunia.com/advisories/28340" source="SECUNIA" adv="1">28340</ref>
      <ref url="http://milw0rm.com/exploits/4845" source="MILW0RM">4845</ref>
    </refs>
    <vuln_soft>
      <prod vendor="runcms" name="runcms">
        <vers num="1.5.3"/>
        <vers num="1.6"/>
        <vers num="1.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0225" published="2008-01-10" name="CVE-2008-0225" modified="2011-10-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 and earlier allows remote attackers to execute arbitrary code via the SDP Abstract attribute in an RTSP session, related to the rmff_dump_header function and related to disregarding the max field.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00592.html" source="FEDORA">FEDORA-2008-0718</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=428620" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=428620</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0163" source="VUPEN" adv="1">ADV-2008-0163</ref>
      <ref url="http://www.ubuntu.com/usn/usn-635-1" source="UBUNTU">USN-635-1</ref>
      <ref url="http://www.securityfocus.com/bid/27198" source="BID">27198</ref>
      <ref url="http://www.novell.com/linux/security/advisories/suse_security_summary_report.html" source="SUSE">SUSE-SR:2008:002</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:045" source="MANDRIVA">MDVSA-2008:045</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:020" source="MANDRIVA">MDVSA-2008:020</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1472" source="DEBIAN">DSA-1472</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=567872" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=567872</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200801-12.xml" source="GENTOO">GLSA-200801-12</ref>
      <ref url="http://secunia.com/advisories/31393" source="SECUNIA" adv="1">31393</ref>
      <ref url="http://secunia.com/advisories/28955" source="SECUNIA" adv="1">28955</ref>
      <ref url="http://secunia.com/advisories/28674" source="SECUNIA" adv="1">28674</ref>
      <ref url="http://secunia.com/advisories/28636" source="SECUNIA" adv="1">28636</ref>
      <ref url="http://secunia.com/advisories/28507" source="SECUNIA" adv="1">28507</ref>
      <ref url="http://secunia.com/advisories/28489" source="SECUNIA" adv="1">28489</ref>
      <ref url="http://secunia.com/advisories/28384" source="SECUNIA" adv="1">28384</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=205197" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=205197</ref>
      <ref url="http://aluigi.altervista.org/adv/xinermffhof-adv.txt" source="MISC">http://aluigi.altervista.org/adv/xinermffhof-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xine" name="xine-lib">
        <vers prev="1" num="1.1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0226" published="2008-01-10" name="CVE-2008-0226" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHello function in handshake.cpp or (2) "input_buffer&amp; operator>>" in yassl_imp.cpp.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39431" source="XF">yassl-inputbufferoperator-bo(39431)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39429" source="XF">yassl-processoldclienthello-bo(39429)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/2780" source="VUPEN">ADV-2008-2780</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0560/references" source="VUPEN">ADV-2008-0560</ref>
      <ref url="http://www.securityfocus.com/bid/31681" source="BID">31681</ref>
      <ref url="http://www.securityfocus.com/bid/27140" source="BID">27140</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485811/100/0/threaded" source="BUGTRAQ">20080104 Pre-auth buffer-overflow in mySQL through yaSSL</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485810/100/0/threaded" source="BUGTRAQ">20080104 Multiple vulnerabilities in yaSSL 1.7.5</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:150" source="MANDRIVA">MDVSA-2008:150</ref>
      <ref url="http://support.apple.com/kb/HT3216" source="CONFIRM">http://support.apple.com/kb/HT3216</ref>
      <ref url="http://secunia.com/advisories/32222" source="SECUNIA">32222</ref>
      <ref url="http://secunia.com/advisories/28324" source="SECUNIA" adv="1">28324</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html" source="APPLE">APPLE-SA-2008-10-09</ref>
      <ref url="http://www.ubuntu.com/usn/usn-588-1" source="UBUNTU">USN-588-1</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1478" source="DEBIAN">DSA-1478</ref>
      <ref url="http://securityreason.com/securityalert/3531" source="SREASON">3531</ref>
      <ref url="http://secunia.com/advisories/29443" source="SECUNIA">29443</ref>
      <ref url="http://secunia.com/advisories/28597" source="SECUNIA">28597</ref>
      <ref url="http://secunia.com/advisories/28419" source="SECUNIA">28419</ref>
      <ref url="http://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.html" source="CONFIRM">http://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.html</ref>
      <ref url="http://bugs.mysql.com/33814" source="CONFIRM">http://bugs.mysql.com/33814</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num=""/>
      </prod>
      <prod vendor="yassl" name="yassl">
        <vers prev="1" num="1.7.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0227" published="2008-01-10" name="CVE-2008-0227" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allows remote attackers to cause a denial of service (crash) via a Hello packet containing a large size value, which triggers a buffer over-read in the HASHwithTransform::Update function in hash.cpp.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39433" source="XF">yassl-hashwithtransformupdate-dos(39433)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/2780" source="VUPEN">ADV-2008-2780</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0560/references" source="VUPEN">ADV-2008-0560</ref>
      <ref url="http://www.securityfocus.com/bid/31681" source="BID">31681</ref>
      <ref url="http://www.securityfocus.com/bid/27140" source="BID">27140</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485810/100/0/threaded" source="BUGTRAQ">20080104 Multiple vulnerabilities in yaSSL 1.7.5</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:150" source="MANDRIVA">MDVSA-2008:150</ref>
      <ref url="http://support.apple.com/kb/HT3216" source="CONFIRM">http://support.apple.com/kb/HT3216</ref>
      <ref url="http://secunia.com/advisories/32222" source="SECUNIA">32222</ref>
      <ref url="http://secunia.com/advisories/28324" source="SECUNIA" adv="1">28324</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html" source="APPLE">APPLE-SA-2008-10-09</ref>
      <ref url="http://www.ubuntu.com/usn/usn-588-1" source="UBUNTU">USN-588-1</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1478" source="DEBIAN">DSA-1478</ref>
      <ref url="http://securityreason.com/securityalert/3531" source="SREASON">3531</ref>
      <ref url="http://secunia.com/advisories/29443" source="SECUNIA">29443</ref>
      <ref url="http://secunia.com/advisories/28597" source="SECUNIA">28597</ref>
      <ref url="http://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.html" source="CONFIRM">http://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.html</ref>
      <ref url="http://bugs.mysql.com/33814" source="CONFIRM">http://bugs.mysql.com/33814</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yassl" name="yassl">
        <vers prev="1" num="1.7.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0228" published="2008-01-10" name="CVE-2008-0228" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in apply.cgi in the Linksys WRT54GL Wireless-G Broadband Router with firmware 4.30.9 allows remote attackers to perform actions as administrators.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39502" source="XF">linksys-apply-csrf(39502)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485853/100/0/threaded" source="BUGTRAQ">20080107 Linksys WRT54 GL - Session riding (CSRF)</ref>
      <ref url="http://secunia.com/advisories/28364" source="SECUNIA" adv="1">28364</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486362/100/0/threaded" source="BUGTRAQ">20080115 Re: Linksys WRT54 GL - Session riding (CSRF)</ref>
      <ref url="http://securityreason.com/securityalert/3534" source="SREASON">3534</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linksys" name="wrt54gl">
        <vers num="4.30.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0229" published="2008-01-10" name="CVE-2008-0229" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The telnet service in LevelOne WBR-3460 4-Port ADSL 2/2+ Wireless Modem Router with firmware 1.00.11 and 1.00.12 does not require authentication, which allows remote attackers on the local or wireless network to obtain administrative access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1019162" source="SECTRACK">1019162</ref>
      <ref url="http://www.securityfocus.com/bid/27183" source="BID">27183</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485935/100/0/threaded" source="BUGTRAQ">20080108 Level-One WBR-3460A Grants Root Access</ref>
      <ref url="http://securityreason.com/securityalert/3533" source="SREASON">3533</ref>
      <ref url="http://secunia.com/advisories/28397" source="SECUNIA">28397</ref>
    </refs>
    <vuln_soft>
      <prod vendor="level_one" name="wbr-3460a">
        <vers num="1.0.11"/>
        <vers num="1.0.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0230" published="2008-01-10" name="CVE-2008-0230" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in php121db.php in osDate 2.0.8 and possibly earlier versions allows remote attackers to execute arbitrary PHP code via a URL in the php121dir parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39567" source="XF">osdate-php121db-file-include(39567)</ref>
      <ref url="http://www.securityfocus.com/bid/27208" source="BID">27208</ref>
      <ref url="http://packetstormsecurity.org/0801-exploits/osdata-lfi.txt" source="MISC">http://packetstormsecurity.org/0801-exploits/osdata-lfi.txt</ref>
      <ref url="http://www.milw0rm.com/exploits/4870" source="MILW0RM">4870</ref>
      <ref url="http://secunia.com/advisories/28420" source="SECUNIA">28420</ref>
    </refs>
    <vuln_soft>
      <prod vendor="osdate" name="osdate">
        <vers num="2.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0231" published="2008-01-10" name="CVE-2008-0231" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in index.php in Tuned Studios (1) Subwoofer, (2) Freeze Theme, (3) Orange Cutout, (4) Lonely Maple, (5) Endless, (6) Classic Theme, and (7) Music Theme webpage templates allow remote attackers to include and execute arbitrary files via ".." sequences in the page parameter.  NOTE: this can be leveraged for remote file inclusion when running in some PHP 5 environments.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39555" source="XF">tunedstudiostemplates-index-file-include(39555)</ref>
      <ref url="http://www.securityfocus.com/bid/27196" source="BID">27196</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485991/100/0/threaded" source="BUGTRAQ">20080109 LFI in Tuned Studios Templates</ref>
      <ref url="http://www.milw0rm.com/exploits/4876" source="MILW0RM">4876</ref>
      <ref url="http://securityreason.com/securityalert/3532" source="SREASON">3532</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tuned_studios" name="classic_theme">
        <vers num=""/>
      </prod>
      <prod vendor="tuned_studios" name="endless">
        <vers num=""/>
      </prod>
      <prod vendor="tuned_studios" name="freeze_theme">
        <vers num=""/>
      </prod>
      <prod vendor="tuned_studios" name="lonely_maple">
        <vers num=""/>
      </prod>
      <prod vendor="tuned_studios" name="music_theme">
        <vers num=""/>
      </prod>
      <prod vendor="tuned_studios" name="orange_cutout">
        <vers num=""/>
      </prod>
      <prod vendor="tuned_studios" name="subwoofer">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0232" published="2008-01-10" name="CVE-2008-0232" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Zero CMS 1.0 Alpha allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to index.php, or the (2) f or t parameters to forums/index.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39530" source="XF">zerocms-index-sql-injection(39530)</ref>
      <ref url="http://www.securityfocus.com/bid/27186" source="BID">27186</ref>
      <ref url="http://packetstormsecurity.org/0801-exploits/zerocms-sql.txt" source="MISC">http://packetstormsecurity.org/0801-exploits/zerocms-sql.txt</ref>
      <ref url="http://www.milw0rm.com/exploits/4864" source="MILW0RM">4864</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zero_cms" name="zero_cms">
        <vers num="1.0_alpha"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0233" published="2008-01-10" name="CVE-2008-0233" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://packetstormsecurity.org/0801-exploits/zerocms-sql.txt" source="MISC">http://packetstormsecurity.org/0801-exploits/zerocms-sql.txt</ref>
      <ref url="http://www.milw0rm.com/exploits/4864" source="MILW0RM">4864</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zero_cms" name="zero_cms">
        <vers num="1.0_alpha"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0234" published="2008-01-10" name="CVE-2008-0234" modified="2011-08-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allows remote attackers to execute arbitrary code via a long Reason-Phrase response to an rtsp:// request, as demonstrated using a 404 error message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/112179" source="CERT-VN">VU#112179</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008//Jul/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2008-07-10</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39601" source="XF">quicktime-rtsp-responses-bo(39601)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/2064/references" source="VUPEN" adv="1">ADV-2008-2064</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0107" source="VUPEN" adv="1">ADV-2008-0107</ref>
      <ref url="http://www.securitytracker.com/id?1019178" source="SECTRACK">1019178</ref>
      <ref url="http://www.securityfocus.com/bid/27225" source="BID">27225</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486268/100/0/threaded" source="BUGTRAQ">20080112 Re: Buffer-overflow in Quicktime Player 7.3.1.70</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486241/100/0/threaded" source="BUGTRAQ">20080112 Re: Re: Buffer-overflow in Quicktime Player 7.3.1.70</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486238/100/0/threaded" source="BUGTRAQ">20080114 Re: [Full-disclosure] Buffer-overflow in Quicktime Player 7.3.1.70</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486174/100/0/threaded" source="BUGTRAQ">20080111 Re: Buffer-overflow in Quicktime Player 7.3.1.70</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486161/100/0/threaded" source="BUGTRAQ">20080111 Re: Re: Buffer-overflow in Quicktime Player 7.3.1.70</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486114/100/0/threaded" source="BUGTRAQ">20080110 Re: Buffer-overflow in Quicktime Player 7.3.1.70</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486091/100/0/threaded" source="BUGTRAQ">20080110 Buffer-overflow in Quicktime Player 7.3.1.70</ref>
      <ref url="http://www.milw0rm.com/exploits/4906" source="MILW0RM">4906</ref>
      <ref url="http://www.milw0rm.com/exploits/4885" source="MILW0RM">4885</ref>
      <ref url="http://securityreason.com/securityalert/3537" source="SREASON">3537</ref>
      <ref url="http://secunia.com/advisories/31034" source="SECUNIA" adv="1">31034</ref>
      <ref url="http://secunia.com/advisories/28423" source="SECUNIA" adv="1">28423</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Feb/msg00001.html" source="APPLE">APPLE-SA-2008-02-06</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.3.1.70"/>
        <vers num="7.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0235" published="2008-01-10" name="CVE-2008-0235" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Microsoft VFP_OLE_Server ActiveX control allows remote attackers to execute arbitrary code by invoking the foxcommand method.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39559" source="XF">microsoft-vfpoleserver-command-execution(39559)</ref>
      <ref url="http://www.securityfocus.com/bid/27199" source="BID">27199</ref>
      <ref url="http://shinnai.altervista.org/exploits/txt/TXT_rNowA1916DKFNUF48NyS.html" source="MISC">http://shinnai.altervista.org/exploits/txt/TXT_rNowA1916DKFNUF48NyS.html</ref>
      <ref url="http://www.milw0rm.com/exploits/4875" source="MILW0RM">4875</ref>
      <ref url="http://secunia.com/advisories/28417" source="SECUNIA">28417</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="vfp_ole_server_activex_control">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0236" published="2008-01-10" name="CVE-2008-0236" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">An ActiveX control for Microsoft Visual FoxPro (vfp6r.dll 6.0.8862.0) allows remote attackers to execute arbitrary commands by invoking the DoCmd method.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39558" source="XF">microsoft-foxserver-command-execution(39558)</ref>
      <ref url="http://www.securityfocus.com/bid/27205" source="BID">27205</ref>
      <ref url="http://shinnai.altervista.org/exploits/txt/TXT_DiWu9j82RCq4zpaQAoxn.html" source="MISC">http://shinnai.altervista.org/exploits/txt/TXT_DiWu9j82RCq4zpaQAoxn.html</ref>
      <ref url="http://www.milw0rm.com/exploits/4873" source="MILW0RM">4873</ref>
      <ref url="http://secunia.com/advisories/28417" source="SECUNIA">28417</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visual_foxpro">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0237" published="2008-01-10" name="CVE-2008-0237" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The Microsoft Rich Textbox ActiveX Control (RICHTX32.OCX) 6.1.97.82 allows remote attackers to execute arbitrary commands by invoking the insecure SaveFile method.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39557" source="XF">microsoft-richtextbox-file-overwrite(39557)</ref>
      <ref url="http://www.securityfocus.com/bid/27201" source="BID">27201</ref>
      <ref url="http://shinnai.altervista.org/exploits/txt/TXT_DZVN8CwCha0I2fI3NeEs.html" source="MISC">http://shinnai.altervista.org/exploits/txt/TXT_DZVN8CwCha0I2fI3NeEs.html</ref>
      <ref url="http://www.milw0rm.com/exploits/4874" source="MILW0RM">4874</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="rich_textbox_control">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0238" published="2008-01-11" name="CVE-2008-0238" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 allow remote attackers to execute arbitrary code via the SDP (1) Title, (2) Author, or (3) Copyright attribute, related to the rmff_dump_header function, different vectors than CVE-2008-0225.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <sols>
      <sol source="nvd">Please see the following link for more information regarding the exploit:

http://aluigi.altervista.org/adv/xinermffhof-adv.txt</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.ubuntu.com/usn/usn-635-1" source="UBUNTU">USN-635-1</ref>
      <ref url="http://secunia.com/advisories/31393" source="SECUNIA">31393</ref>
      <ref url="http://secunia.com/advisories/28384" source="SECUNIA" adv="1">28384</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:045" source="MANDRIVA">MDVSA-2008:045</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:020" source="MANDRIVA">MDVSA-2008:020</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200801-12.xml" source="GENTOO">GLSA-200801-12</ref>
      <ref url="http://secunia.com/advisories/28955" source="SECUNIA">28955</ref>
      <ref url="http://secunia.com/advisories/28674" source="SECUNIA">28674</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=205197" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=205197</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xine" name="xine-lib">
        <vers prev="1" num="1.1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0239" published="2008-01-11" name="CVE-2008-0239" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allow remote attackers to inject arbitrary HTML or web script via the (1) cntry or lang parameters to /idm/login.jsp, (2) resultsForm parameter to /idm/account/findForSelect.jsp, or (3) activeControl parameter to /idm/user/main.jsp.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486076/100/0/threaded" source="BUGTRAQ" patch="1">20080110 PR07-06, PR07-07, PR07-08, PR07-09, PR07-10, PR07-12: Several XSS, Cross-domain Redirection and Frame Injection on Sun Java System Identity Manager</ref>
      <ref url="http://www.procheckup.com/Vulnerability_PR07-08.php" source="MISC" patch="1">http://www.procheckup.com/Vulnerability_PR07-08.php</ref>
      <ref url="http://www.procheckup.com/Vulnerability_PR07-07.php" source="MISC" patch="1">http://www.procheckup.com/Vulnerability_PR07-07.php</ref>
      <ref url="http://www.procheckup.com/Vulnerability_PR07-06.php" source="MISC" patch="1">http://www.procheckup.com/Vulnerability_PR07-06.php</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39583" source="XF">sun-identity-main-xss(39583)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39582" source="XF">sun-identity-resultsform-xss(39582)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39581" source="XF">sun-identity-lang-xss(39581)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39580" source="XF">sun-identity-login-xss(39580)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0089" source="VUPEN">ADV-2008-0089</ref>
      <ref url="http://www.securityfocus.com/bid/27214" source="BID">27214</ref>
      <ref url="http://www.procheckup.com/Vulnerability_PR07-09.php" source="MISC">http://www.procheckup.com/Vulnerability_PR07-09.php</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103180-1" source="SUNALERT">103180</ref>
      <ref url="http://secunia.com/advisories/28356" source="SECUNIA" adv="1">28356</ref>
      <ref url="http://www.securitytracker.com/id?1019175" source="SECTRACK">1019175</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200558-1" source="SUNALERT">200558</ref>
      <ref url="http://securityreason.com/securityalert/3535" source="SREASON">3535</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_identity_manager">
        <vers num="6.0" edition="sp1"/>
        <vers num="6.0" edition="sp2"/>
        <vers num="6.0" edition="sp3"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0240" published="2008-01-11" name="CVE-2008-0240" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">/idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via the helpUrl parameter, aka "frame injection."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.procheckup.com/Vulnerability_PR07-10.php" source="MISC" patch="1">http://www.procheckup.com/Vulnerability_PR07-10.php</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39586" source="XF">sun-identity-index-frame-injection(39586)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0089" source="VUPEN">ADV-2008-0089</ref>
      <ref url="http://www.securityfocus.com/bid/27214" source="BID">27214</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486076/100/0/threaded" source="BUGTRAQ">20080110 PR07-06, PR07-07, PR07-08, PR07-09, PR07-10, PR07-12: Several XSS, Cross-domain Redirection and Frame Injection on Sun Java System Identity Manager</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103180-1" source="SUNALERT">103180</ref>
      <ref url="http://secunia.com/advisories/28356" source="SECUNIA" adv="1">28356</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200558-1" source="SUNALERT">200558</ref>
      <ref url="http://securityreason.com/securityalert/3535" source="SREASON">3535</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_identity_manager">
        <vers num="6.0" edition="sp1"/>
        <vers num="6.0" edition="sp2"/>
        <vers num="6.0" edition="sp3"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0241" published="2008-01-11" name="CVE-2008-0241" modified="2011-08-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Open redirect vulnerability in /idm/user/login.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the nextPage parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.procheckup.com/Vulnerability_PR07-12.php" source="MISC" patch="1">http://www.procheckup.com/Vulnerability_PR07-12.php</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200558-1" source="SUNALERT" patch="1" adv="1">200558</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103180-1" source="SUNALERT" patch="1" adv="1">103180</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39590" source="XF">sun-identity-login-security-bypass(39590)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0089" source="VUPEN" adv="1">ADV-2008-0089</ref>
      <ref url="http://www.securityfocus.com/bid/27214" source="BID">27214</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486076/100/0/threaded" source="BUGTRAQ">20080110 PR07-06, PR07-07, PR07-08, PR07-09, PR07-10, PR07-12: Several XSS, Cross-domain Redirection and Frame Injection on Sun Java System Identity Manager</ref>
      <ref url="http://securityreason.com/securityalert/3535" source="SREASON">3535</ref>
      <ref url="http://secunia.com/advisories/28356" source="SECUNIA" adv="1">28356</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_identity_manager">
        <vers num="6.0" edition="sp1"/>
        <vers num="6.0" edition="sp2"/>
        <vers num="6.0" edition="sp3"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0242" published="2008-01-11" name="CVE-2008-0242" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in libdevinfo in Sun Solaris 10 allows local users to access files and gain privileges via unknown vectors, related to login device permissions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0131" source="VUPEN">ADV-2008-0131</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103165-1" source="SUNALERT">103165</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39629" source="XF">solaris-libdevinfo-privilege-escalation(39629)</ref>
      <ref url="http://www.securitytracker.com/id?1019187" source="SECTRACK">1019187</ref>
      <ref url="http://www.securityfocus.com/bid/27253" source="BID">27253</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200641-1" source="SUNALERT">200641</ref>
      <ref url="http://secunia.com/advisories/28493" source="SECUNIA">28493</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5211" source="OVAL" sig="1">oval:org.mitre.oval:def:5211</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition=""/>
        <vers num="10.0" edition=":sparc"/>
        <vers num="10.0" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0243" published="2008-01-11" name="CVE-2008-0243" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Lotus Domino 7.0.2 before Fix Pack 3 allows attackers to cause a denial of service via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39588" source="XF">lotus-domino-unspecified-dos(39588)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0086" source="VUPEN">ADV-2008-0086</ref>
      <ref url="http://www.securityfocus.com/bid/27215" source="BID">27215</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg27011539" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg27011539</ref>
      <ref url="http://secunia.com/advisories/28411" source="SECUNIA" adv="1">28411</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2" edition=""/>
        <vers num="7.0.2" edition=":fp1"/>
        <vers num="7.0.2" edition=":fp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0244" published="2008-01-11" name="CVE-2008-0244" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&amp;&amp;" and other shell metacharacters in exec_sdbinfo and other unspecified commands, which are executed when MaxDB invokes cons.exe.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39573" source="XF">maxdb-system-command-execution(39573)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0104" source="VUPEN">ADV-2008-0104</ref>
      <ref url="http://www.securitytracker.com/id?1019171" source="SECTRACK">1019171</ref>
      <ref url="http://www.securityfocus.com/bid/27206" source="BID">27206</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486039/100/0/threaded" source="BUGTRAQ">20080109 Pre-auth remote commands execution in SAP MaxDB 7.6.03.07</ref>
      <ref url="http://www.milw0rm.com/exploits/4877" source="MILW0RM">4877</ref>
      <ref url="http://secunia.com/advisories/28409" source="SECUNIA" adv="1">28409</ref>
      <ref url="http://aluigi.altervista.org/adv/sapone-adv.txt" source="MISC">http://aluigi.altervista.org/adv/sapone-adv.txt</ref>
      <ref url="http://securityreason.com/securityalert/3536" source="SREASON">3536</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="maxdb">
        <vers prev="1" num="7.6.3_build_007"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0245" published="2008-01-11" name="CVE-2008-0245" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">admin.php in UploadImage 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain administrator privileges via the pass parameter in a nopass (Set Password) action.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39571" source="XF">uploadimage-admin-command-execution(39571)</ref>
      <ref url="http://www.securityfocus.com/bid/27203" source="BID">27203</ref>
      <ref url="http://www.milw0rm.com/exploits/4871" source="MILW0RM">4871</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uploadscript" name="uploadimage">
        <vers num="1.0"/>
      </prod>
      <prod vendor="uploadscript" name="uploadscript">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0246" published="2008-01-11" name="CVE-2008-0246" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">admin.php in UploadScript 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain administrator privileges via the pass parameter in a nopass (Set Password) action.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39570" source="XF">uploadscript-admin-command-execution(39570)</ref>
      <ref url="http://www.securityfocus.com/bid/27203" source="BID">27203</ref>
      <ref url="http://www.milw0rm.com/exploits/4871" source="MILW0RM">4871</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uploadscript" name="uploadimage">
        <vers num="1.0"/>
      </prod>
      <prod vendor="uploadscript" name="uploadscript">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0247" published="2008-01-11" name="CVE-2008-0247" modified="2011-10-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the Express Backup Server service (dsmsvc.exe) in IBM Tivoli Storage Manager (TSM) Express 5.3 before 5.3.7.3 allows remote attackers to execute arbitrary code via a packet with a large length value.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27235" source="BID" patch="1">27235</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21291536" source="CONFIRM" patch="1">http://www-1.ibm.com/support/docview.wss?uid=swg21291536</ref>
      <ref url="http://secunia.com/advisories/28440" source="SECUNIA" patch="1" adv="1">28440</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39604" source="XF">ibm-tsmexpressserver-bo(39604)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-08-001.html" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-08-001.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0106" source="VUPEN" adv="1">ADV-2008-0106</ref>
      <ref url="http://www.securitytracker.com/id?1019182" source="SECTRACK">1019182</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486270/100/0/threaded" source="BUGTRAQ">20080114 ZDI-08-001: IBM Tivoli Storage Manager Express Backup Server Heap Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_storage_manager_express">
        <vers prev="1" num="5.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0248" published="2008-01-11" name="CVE-2008-0248" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in an ActiveX control in ccpm_0237.dll for StreamAudio ChainCast ProxyManager allows remote attackers to execute arbitrary code via a long URL argument to the InternalTuneIn method.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39622" source="XF">streamaudio-chaincastproxymanager-bo(39622)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0133" source="VUPEN">ADV-2008-0133</ref>
      <ref url="http://www.securityfocus.com/bid/27247" source="BID">27247</ref>
      <ref url="http://www.milw0rm.com/exploits/4894" source="MILW0RM">4894</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059572.html" source="FULLDISC">20080111 StreamAudio ChainCast ProxyManager ccpm_0237.dll Buffer Overflow</ref>
      <ref url="http://secunia.com/advisories/28461" source="SECUNIA">28461</ref>
    </refs>
    <vuln_soft>
      <prod vendor="streamaudio" name="chaincast_proxymanager_activex_control">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0249" published="2008-01-11" name="CVE-2008-0249" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebquest.php, which leaks the credentials in an error message if a call to /usr/bin/mysqldump fails.  NOTE: this might only be an issue in limited environments.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39572" source="XF">phpwebquest-backup-information-disclosure(39572)</ref>
      <ref url="http://www.securityfocus.com/bid/27202" source="BID">27202</ref>
      <ref url="http://www.milw0rm.com/exploits/4872" source="MILW0RM">4872</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpwebquest" name="phpwebquest">
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0250" published="2008-01-11" name="CVE-2008-0250" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a Studio Solution (.SLN) file with a long Project line.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27250" source="BID">27250</ref>
      <ref url="http://www.milw0rm.com/exploits/4892" source="MILW0RM">4892</ref>
      <ref url="http://shinnai.altervista.org/exploits/txt/TXT_PoEOrFM8py30PXrDF7IY.html" source="MISC">http://shinnai.altervista.org/exploits/txt/TXT_PoEOrFM8py30PXrDF7IY.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41826" source="XF">visualinterdev-sln-project-bo(41826)</ref>
      <ref url="http://secunia.com/advisories/28482" source="SECUNIA">28482</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visual_interdev">
        <vers num="6.0" edition="sp6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0251" published="2008-01-11" name="CVE-2008-0251" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in PhotoPost vBGallery before 2.4.2 allows remote attackers to upload and execute arbitrary files via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39621" source="XF">vbgallery-unspecified-code-execution(39621)</ref>
      <ref url="http://www.photopost.com/forum/showthread.php?t=134910" source="CONFIRM">http://www.photopost.com/forum/showthread.php?t=134910</ref>
      <ref url="http://www.photopost.com/forum/showthread.php?t=134909" source="CONFIRM">http://www.photopost.com/forum/showthread.php?t=134909</ref>
      <ref url="http://secunia.com/advisories/28430" source="SECUNIA" adv="1">28430</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photopost" name="photopost_vbgallery">
        <vers prev="1" num="2.4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0252" published="2008-01-11" name="CVE-2008-0252" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the _get_file_path function in (1) lib/sessions.py in CherryPy 3.0.x up to 3.0.2, (2) filter/sessionfilter.py in CherryPy 2.1, and (3) filter/sessionfilter.py in CherryPy 2.x allows remote attackers to create or delete arbitrary files, and possibly read and write portions of arbitrary files, via a crafted session id in a cookie.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.cherrypy.org/changeset/1775" source="CONFIRM" patch="1">http://www.cherrypy.org/changeset/1775</ref>
      <ref url="http://www.cherrypy.org/changeset/1774" source="CONFIRM" patch="1">http://www.cherrypy.org/changeset/1774</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00297.html" source="FEDORA">FEDORA-2008-0333</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00240.html" source="FEDORA">FEDORA-2008-0299</ref>
      <ref url="https://bugs.gentoo.org/show_bug.cgi?id=204829" source="CONFIRM">https://bugs.gentoo.org/show_bug.cgi?id=204829</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0039" source="VUPEN">ADV-2008-0039</ref>
      <ref url="http://www.cherrypy.org/ticket/744" source="CONFIRM">http://www.cherrypy.org/ticket/744</ref>
      <ref url="http://www.cherrypy.org/changeset/1776" source="CONFIRM">http://www.cherrypy.org/changeset/1776</ref>
      <ref url="http://secunia.com/advisories/28354" source="SECUNIA" adv="1">28354</ref>
      <ref url="http://secunia.com/advisories/28353" source="SECUNIA">28353</ref>
      <ref url="https://issues.rpath.com/browse/RPL-2127" source="CONFIRM">https://issues.rpath.com/browse/RPL-2127</ref>
      <ref url="http://www.securityfocus.com/bid/27181" source="BID">27181</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487001/100/0/threaded" source="BUGTRAQ">20080124 rPSA-2008-0030-1 CherryPy</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1481" source="DEBIAN">DSA-1481</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200801-11.xml" source="GENTOO">GLSA-200801-11</ref>
      <ref url="http://secunia.com/advisories/28769" source="SECUNIA">28769</ref>
      <ref url="http://secunia.com/advisories/28620" source="SECUNIA">28620</ref>
      <ref url="http://secunia.com/advisories/28611" source="SECUNIA">28611</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cherrypy" name="cherrypy">
        <vers prev="1" num="2.1.0"/>
        <vers prev="1" num="3.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0253" published="2008-01-15" name="CVE-2008-0253" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in full_text.php in Binn SBuilder allows remote attackers to execute arbitrary SQL commands via the nid parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27264" source="BID">27264</ref>
      <ref url="http://www.milw0rm.com/exploits/4904" source="MILW0RM">4904</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39634" source="XF">binnsbuilder-fulltext-sql-injection(39634)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486265/100/0/threaded" source="BUGTRAQ">20080114 Binn SBuilder (nid) Remote Blind Sql Injection Vulnerabily</ref>
    </refs>
    <vuln_soft>
      <prod vendor="binn" name="sbuilder">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0254" published="2008-01-15" name="CVE-2008-0254" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in activate.php in TutorialCMS (aka Photoshop Tutorials) 1.02, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the userName parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27263" source="BID">27263</ref>
      <ref url="http://www.milw0rm.com/exploits/4901" source="MILW0RM">4901</ref>
      <ref url="http://secunia.com/advisories/28446" source="SECUNIA" adv="1">28446</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39642" source="XF">tutorialcms-activate-sql-injection(39642)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wavelink_media" name="tutorialcms">
        <vers num="1.02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0255" published="2008-01-15" name="CVE-2008-0255" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in archive.php in iGaming 1.5, and 1.3.1 and earlier, allows remote attackers to execute arbitrary SQL commands via the section parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39598" source="XF">igamingcms-archive-sql-injection(39598)</ref>
      <ref url="http://www.securityfocus.com/bid/27230" source="BID">27230</ref>
      <ref url="http://www.milw0rm.com/exploits/4886" source="MILW0RM">4886</ref>
      <ref url="http://secunia.com/advisories/28426" source="SECUNIA" adv="1">28426</ref>
    </refs>
    <vuln_soft>
      <prod vendor="igamingcms" name="igaming_cms">
        <vers prev="1" num="1.3.1"/>
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0256" published="2008-01-15" name="CVE-2008-0256" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Matteo Binda ASP Photo Gallery 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) Imgbig.asp, (b) thumb.asp, and (c) thumbricerca.asp and the (2) ricerca parameter to (d) thumbricerca.asp.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27262" source="BID">27262</ref>
      <ref url="http://www.milw0rm.com/exploits/4900" source="MILW0RM">4900</ref>
      <ref url="http://secunia.com/advisories/28447" source="SECUNIA" adv="1">28447</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39646" source="XF">aspphotogallery-multiple-sql-injection(39646)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matteo_binda" name="asp_photo_gallery">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0257" published="2008-01-15" name="CVE-2008-0257" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.pl in Dansie Search Engine 2.7 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/28465" source="SECUNIA" adv="1">28465</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39636" source="XF">dansiesearchengine-search-xss(39636)</ref>
      <ref url="http://www.securityfocus.com/bid/27269" source="BID">27269</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dansie" name="search_engine">
        <vers num="2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0258" published="2008-01-15" name="CVE-2008-0258" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in PHP Running Management (phpRunMan) before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the message parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27268" source="BID" patch="1">27268</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=568237&amp;group_id=103505" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=568237&amp;group_id=103505</ref>
      <ref url="http://secunia.com/advisories/28474" source="SECUNIA" patch="1" adv="1">28474</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1204199&amp;group_id=103505&amp;atid=634992" source="CONFIRM">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1204199&amp;group_id=103505&amp;atid=634992</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39639" source="XF">phprunningmanagement-index-xss(39639)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_running_management" name="phprunman">
        <vers prev="1" num="1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0259" published="2008-01-15" name="CVE-2008-0259" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in _mg/php/mg_thumbs.php in minimal Gallery 0.8 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) thumbcat and (2) thumb parameters.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27265" source="BID">27265</ref>
      <ref url="http://www.milw0rm.com/exploits/4902" source="MILW0RM">4902</ref>
      <ref url="http://secunia.com/advisories/28391" source="SECUNIA" adv="1">28391</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39649" source="XF">minimalgallery-mgthumbs-file-include(39649)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="minimal_design" name="minimal_gallery">
        <vers num="0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0260" published="2008-01-15" name="CVE-2008-0260" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">minimal Gallery 0.8 allows remote attackers to obtain configuration information via a direct request to php_info.php, which calls the phpinfo function.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/4902" source="MILW0RM">4902</ref>
      <ref url="http://secunia.com/advisories/28391" source="SECUNIA" adv="1">28391</ref>
    </refs>
    <vuln_soft>
      <prod vendor="minimal_design" name="minimal_gallery">
        <vers num="0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0261" published="2008-01-15" name="CVE-2008-0261" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the search component and module in Mambo 4.5.x and 4.6.x allows remote attackers to cause a denial of service (query flood) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27239" source="BID" patch="1">27239</ref>
      <ref url="http://secunia.com/advisories/28392" source="SECUNIA" patch="1" adv="1">28392</ref>
      <ref url="http://forum.mambo-foundation.org/showthread.php?t=9651" source="CONFIRM" patch="1">http://forum.mambo-foundation.org/showthread.php?t=9651</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39613" source="XF">mambo-search-dos(39613)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mambo" name="mambo_open_source">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0262" published="2008-01-15" name="CVE-2008-0262" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in includes/articleblock.php in Agares PhpAutoVideo 2.21 allows remote attackers to execute arbitrary SQL commands via the articlecat parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39641" source="XF">agares-articleblock-sql-injection(39641)</ref>
      <ref url="http://www.securityfocus.com/bid/27258" source="BID">27258</ref>
      <ref url="http://www.milw0rm.com/exploits/4905" source="MILW0RM">4905</ref>
      <ref url="http://www.milw0rm.com/exploits/4898" source="MILW0RM">4898</ref>
    </refs>
    <vuln_soft>
      <prod vendor="agares_media" name="phpautovideo">
        <vers num="2.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0263" published="2008-01-15" name="CVE-2008-0263" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The SIP module in Ingate Firewall before 4.6.1 and SIParator before 4.6.1 does not reuse SIP media ports in unspecified call hold and send-only stream scenarios, which allows remote attackers to cause a denial of service (port exhaustion) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0108" source="VUPEN">ADV-2008-0108</ref>
      <ref url="http://www.securitytracker.com/id?1019177" source="SECTRACK">1019177</ref>
      <ref url="http://www.securitytracker.com/id?1019176" source="SECTRACK">1019176</ref>
      <ref url="http://www.securityfocus.com/bid/27222" source="BID">27222</ref>
      <ref url="http://www.ingate.com/relnote-461.php" source="CONFIRM" adv="1">http://www.ingate.com/relnote-461.php</ref>
      <ref url="http://secunia.com/advisories/28394" source="SECUNIA" adv="1">28394</ref>
      <ref url="http://osvdb.org/40365" source="OSVDB">40365</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ingate" name="firewall">
        <vers prev="1" num="4.6"/>
      </prod>
      <prod vendor="ingate" name="ingate_siparator">
        <vers prev="1" num="4.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0264" published="2008-01-15" name="CVE-2008-0264" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Meta Tags (aka Nodewords) 5.x-1.6 module for Drupal, when images are permitted in node bodies, allows remote authenticated users to execute arbitrary code via unspecified vectors involving creation of a node.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://drupal.org/node/209759" source="CONFIRM" patch="1">http://drupal.org/node/209759</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0129" source="VUPEN">ADV-2008-0129</ref>
      <ref url="http://secunia.com/advisories/28478" source="SECUNIA" adv="1">28478</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39638" source="XF">drupal-metatags-code-execution(39638)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="meta_tags_module">
        <vers prev="1" num="5.x-1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0265" published="2008-01-15" name="CVE-2008-0265" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the Search function in the web management interface in F5 BIG-IP 9.4.3 allow remote attackers to inject arbitrary web script or HTML via the SearchString parameter to (1) list_system.jsp, (2) list_pktfilter.jsp, (3) list_ltm.jsp, (4) resources_audit.jsp, and (5) list_asm.jsp in tmui/Control/jspmap/tmui/system/log/; and (6) list.jsp in certain directories.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39632" source="XF">f5bigip-searchstring-xss(39632)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0181" source="VUPEN">ADV-2008-0181</ref>
      <ref url="http://www.securitytracker.com/id?1019190" source="SECTRACK">1019190</ref>
      <ref url="http://www.securityfocus.com/bid/27272" source="BID">27272</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486217/100/0/threaded" source="BUGTRAQ">20080114 F5 BIG-IP Web Management List Search XSS</ref>
      <ref url="http://secunia.com/advisories/28505" source="SECUNIA" adv="1">28505</ref>
      <ref url="http://securityreason.com/securityalert/3545" source="SREASON">3545</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f5" name="big-ip">
        <vers num="9.4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2008-0266" published="2008-01-15" name="CVE-2008-0266" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in admin.php in eTicket 1.5.5.2 allows remote attackers to change the administrative password and possibly perform other administrative tasks.  NOTE: either the old password must be known, or the attacker must leverage a separate SQL injection vulnerability.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39490" source="XF">eticket-admin-csrf(39490)</ref>
      <ref url="http://www.securityfocus.com/bid/27173" source="BID">27173</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485835/100/0/threaded" source="BUGTRAQ">20080106 eTicket 1.5.5.2 Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/28331" source="SECUNIA" adv="1">28331</ref>
      <ref url="http://securityreason.com/securityalert/3542" source="SREASON">3542</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eticket" name="eticket">
        <vers num="1.5.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0267" published="2008-01-15" name="CVE-2008-0267" modified="2009-09-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in eTicket 1.5.5.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) status, (2) sort, and (3) way parameters to search.php; and allow remote authenticated administrators to execute arbitrary SQL commands via the (4) msg and (5) password parameters to admin.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39489" source="XF">eticket-search-sql-injection(39489)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39487" source="XF">eticket-admin-sql-injection(39487)</ref>
      <ref url="http://www.securityfocus.com/bid/27173" source="BID">27173</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485835/100/0/threaded" source="BUGTRAQ">20080106 eTicket 1.5.5.2 Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/28331" source="SECUNIA" adv="1">28331</ref>
      <ref url="http://securityreason.com/securityalert/3542" source="SREASON">3542</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eticket" name="eticket">
        <vers num="1.5.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0268" published="2008-01-15" name="CVE-2008-0268" modified="2010-08-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in view.php in eTicket 1.5.5.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39488" source="XF">eticket-view-xss(39488)</ref>
      <ref url="http://www.securityfocus.com/bid/27173" source="BID">27173</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485835/100/0/threaded" source="BUGTRAQ">20080106 eTicket 1.5.5.2 Multiple Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/3542" source="SREASON">3542</ref>
      <ref url="http://secunia.com/advisories/28331" source="SECUNIA" adv="1">28331</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eticket" name="eticket">
        <vers num="1.5.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0269" published="2008-01-15" name="CVE-2008-0269" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in the dotoprocs function in Sun Solaris 10 allows local users to cause a denial of service (panic) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103188-1" source="SUNALERT" patch="1">103188</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0130" source="VUPEN">ADV-2008-0130</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39631" source="XF">solaris-dotoprocs-dos(39631)</ref>
      <ref url="http://www.securitytracker.com/id?1019186" source="SECTRACK">1019186</ref>
      <ref url="http://www.securityfocus.com/bid/27260" source="BID">27260</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201513-1" source="SUNALERT">201513</ref>
      <ref url="http://secunia.com/advisories/28491" source="SECUNIA">28491</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5400" source="OVAL" sig="1">oval:org.mitre.oval:def:5400</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0270" published="2008-01-15" name="CVE-2008-0270" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in TaskFreak! 0.6.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via the sContext parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/4899" source="MILW0RM">4899</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39645" source="XF">taskfreak-index-sql-injection(39645)</ref>
      <ref url="http://www.securityfocus.com/bid/27257" source="BID">27257</ref>
      <ref url="http://secunia.com/advisories/28448" source="SECUNIA">28448</ref>
    </refs>
    <vuln_soft>
      <prod vendor="taskfreak" name="taskfreak">
        <vers prev="1" num="0.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0271" published="2008-01-15" name="CVE-2008-0271" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The editor deletion form in BUEditor 4.7.x before 4.7.x-1.0 and 5.x before 5.x-1.1, a module for Drupal, does not follow Drupal's Forms API submission model, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and delete custom editor interfaces.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/28418" source="SECUNIA" patch="1" adv="1">28418</ref>
      <ref url="http://drupal.org/node/208534" source="CONFIRM" patch="1">http://drupal.org/node/208534</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39614" source="XF">drupal-bueditor-csrf(39614)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0128" source="VUPEN">ADV-2008-0128</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="bueditor">
        <vers prev="1" num="4.7.x-1.0"/>
        <vers prev="1" num="5.x-1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0272" published="2008-01-15" name="CVE-2008-0272" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in the aggregator module in Drupal 4.7.x before 4.7.11 and 5.x before 5.6 allows remote attackers to delete items from a feed as privileged users.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27238" source="BID" patch="1">27238</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39617" source="XF">drupal-aggregator-csrf(39617)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0134" source="VUPEN">ADV-2008-0134</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0127" source="VUPEN">ADV-2008-0127</ref>
      <ref url="http://www.vbdrupal.org/forum/showthread.php?t=1349" source="CONFIRM">http://www.vbdrupal.org/forum/showthread.php?t=1349</ref>
      <ref url="http://www.vbdrupal.org/forum/showthread.php?p=6878" source="CONFIRM">http://www.vbdrupal.org/forum/showthread.php?p=6878</ref>
      <ref url="http://secunia.com/advisories/28486" source="SECUNIA">28486</ref>
      <ref url="http://secunia.com/advisories/28422" source="SECUNIA" adv="1">28422</ref>
      <ref url="http://drupal.org/node/208562" source="CONFIRM">http://drupal.org/node/208562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="drupal">
        <vers num="4.0.0"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0_rc"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.5"/>
        <vers num="4.5.1"/>
        <vers num="4.5.2"/>
        <vers num="4.5.3"/>
        <vers num="4.5.4"/>
        <vers num="4.5.5"/>
        <vers num="4.5.6"/>
        <vers num="4.5.7"/>
        <vers num="4.5.8"/>
        <vers num="4.6"/>
        <vers num="4.6.1"/>
        <vers num="4.6.10"/>
        <vers num="4.6.11"/>
        <vers num="4.6.2"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="4.6.5"/>
        <vers num="4.6.6"/>
        <vers num="4.6.7"/>
        <vers num="4.6.8"/>
        <vers num="4.6.9"/>
        <vers num="4.7"/>
        <vers num="4.7.1"/>
        <vers num="4.7.10"/>
        <vers num="4.7.2"/>
        <vers num="4.7.3"/>
        <vers num="4.7.4"/>
        <vers num="4.7.5"/>
        <vers num="4.7.6"/>
        <vers num="4.7.7"/>
        <vers num="4.7.8"/>
        <vers num="4.7.9"/>
        <vers num="4.7_rev_1.15"/>
        <vers num="4.7_rev_1.2"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.1_rev1.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5."/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0273" published="2008-01-15" name="CVE-2008-0273" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Interpretation conflict in Drupal 4.7.x before 4.7.11 and 5.x before 5.6, when Internet Explorer 6 is used, allows remote attackers to conduct cross-site scripting (XSS) attacks via invalid UTF-8 byte sequences, which are not processed as UTF-8 by Drupal's HTML filtering, but are processed as UTF-8 by Internet Explorer, effectively removing characters from the document and defeating the HTML protection mechanism.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27238" source="BID" patch="1">27238</ref>
      <ref url="http://secunia.com/advisories/28422" source="SECUNIA" patch="1">28422</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39619" source="XF">drupal-utf8-xss(39619)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0134" source="VUPEN">ADV-2008-0134</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0127" source="VUPEN">ADV-2008-0127</ref>
      <ref url="http://www.vbdrupal.org/forum/showthread.php?t=1349" source="CONFIRM">http://www.vbdrupal.org/forum/showthread.php?t=1349</ref>
      <ref url="http://www.vbdrupal.org/forum/showthread.php?p=6878" source="CONFIRM">http://www.vbdrupal.org/forum/showthread.php?p=6878</ref>
      <ref url="http://secunia.com/advisories/28486" source="SECUNIA">28486</ref>
      <ref url="http://drupal.org/node/208564" source="CONFIRM">http://drupal.org/node/208564</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="drupal">
        <vers num="4.0.0"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0_rc"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.5"/>
        <vers num="4.5.1"/>
        <vers num="4.5.2"/>
        <vers num="4.5.3"/>
        <vers num="4.5.4"/>
        <vers num="4.5.5"/>
        <vers num="4.5.6"/>
        <vers num="4.5.7"/>
        <vers num="4.5.8"/>
        <vers num="4.6"/>
        <vers num="4.6.1"/>
        <vers num="4.6.10"/>
        <vers num="4.6.11"/>
        <vers num="4.6.2"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="4.6.5"/>
        <vers num="4.6.6"/>
        <vers num="4.6.7"/>
        <vers num="4.6.8"/>
        <vers num="4.6.9"/>
        <vers num="4.7"/>
        <vers num="4.7.1"/>
        <vers num="4.7.10"/>
        <vers num="4.7.2"/>
        <vers num="4.7.3"/>
        <vers num="4.7.4"/>
        <vers num="4.7.5"/>
        <vers num="4.7.6"/>
        <vers num="4.7.7"/>
        <vers num="4.7.8"/>
        <vers num="4.7.9"/>
        <vers num="4.7_rev_1.15"/>
        <vers num="4.7_rev_1.2"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.1_rev1.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5."/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2008-0274" published="2008-01-15" name="CVE-2008-0274" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote attackers to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27238" source="BID" patch="1">27238</ref>
      <ref url="http://secunia.com/advisories/28422" source="SECUNIA" patch="1">28422</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39605" source="XF">drupal-theme-xss(39605)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0134" source="VUPEN">ADV-2008-0134</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0127" source="VUPEN">ADV-2008-0127</ref>
      <ref url="http://www.vbdrupal.org/forum/showthread.php?t=1349" source="CONFIRM">http://www.vbdrupal.org/forum/showthread.php?t=1349</ref>
      <ref url="http://www.vbdrupal.org/forum/showthread.php?p=6878" source="CONFIRM">http://www.vbdrupal.org/forum/showthread.php?p=6878</ref>
      <ref url="http://secunia.com/advisories/28486" source="SECUNIA">28486</ref>
      <ref url="http://drupal.org/node/208565" source="CONFIRM">http://drupal.org/node/208565</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="drupal">
        <vers num="4.7"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0275" published="2008-01-15" name="CVE-2008-0275" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Atom 4.7 before 4.7.x-1.0 and 5.x before 5.x-1.0 module for Drupal does not properly manage permissions for node (1) titles, (2) teasers, and (3) bodies, which might allow remote attackers to gain access to syndicated content.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39607" source="XF">drupal-atom-security-bypass(39607)</ref>
      <ref url="http://drupal.org/node/208527" source="CONFIRM">http://drupal.org/node/208527</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="atom_module">
        <vers prev="1" num="4.7"/>
        <vers prev="1" num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0276" published="2008-01-15" name="CVE-2008-0276" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Devel module before 5.x-0.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via a site variable, related to lack of escaping of the variable table.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39606" source="XF">drupal-devel-variable-xss(39606)</ref>
      <ref url="http://drupal.org/node/208524" source="CONFIRM">http://drupal.org/node/208524</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="drupal">
        <vers num="4.0.0"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0_rc"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.5"/>
        <vers num="4.5.1"/>
        <vers num="4.5.2"/>
        <vers num="4.5.3"/>
        <vers num="4.5.4"/>
        <vers num="4.5.5"/>
        <vers num="4.5.6"/>
        <vers num="4.5.7"/>
        <vers num="4.5.8"/>
        <vers num="4.6"/>
        <vers num="4.6.1"/>
        <vers num="4.6.10"/>
        <vers num="4.6.11"/>
        <vers num="4.6.2"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="4.6.5"/>
        <vers num="4.6.6"/>
        <vers num="4.6.7"/>
        <vers num="4.6.8"/>
        <vers num="4.6.9"/>
        <vers num="4.7"/>
        <vers num="4.7.1"/>
        <vers num="4.7.10"/>
        <vers num="4.7.2"/>
        <vers num="4.7.3"/>
        <vers num="4.7.4"/>
        <vers num="4.7.5"/>
        <vers num="4.7.6"/>
        <vers num="4.7.7"/>
        <vers num="4.7.8"/>
        <vers num="4.7.9"/>
        <vers num="4.7_rev_1.15"/>
        <vers num="4.7_rev_1.2"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.1_rev1.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5."/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0277" published="2008-01-15" name="CVE-2008-0277" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Fileshare module for Drupal allows remote authenticated users with node-creation privileges to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39609" source="XF">drupal-fileshare-code-execution(39609)</ref>
      <ref url="http://drupal.org/node/208537" source="CONFIRM">http://drupal.org/node/208537</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="fileshare_module">
        <vers num="4.7.x"/>
        <vers num="5.x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0278" published="2008-01-15" name="CVE-2008-0278" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in X7 Chat 2.0.5 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the day parameter in a sm_window action.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39656" source="XF">x7chatday-sql-injection(39656)</ref>
      <ref url="http://www.securityfocus.com/bid/27277" source="BID">27277</ref>
      <ref url="http://www.milw0rm.com/exploits/4907" source="MILW0RM">4907</ref>
      <ref url="http://secunia.com/advisories/28503" source="SECUNIA" adv="1">28503</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x7_group" name="x7_chat">
        <vers prev="1" num="2.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0279" published="2008-01-15" name="CVE-2008-0279" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in liretopic.php in Xforum 1.4 and possibly others allows remote attackers to execute arbitrary SQL commands via the topic parameter.  NOTE: the categorie parameter might also be affected.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39654" source="XF">xforum-liretopic-sql-injection(39654)</ref>
      <ref url="http://www.securityfocus.com/bid/27278" source="BID">27278</ref>
      <ref url="http://www.milw0rm.com/exploits/4908" source="MILW0RM">4908</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xforum" name="xforum">
        <vers num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0280" published="2008-01-15" name="CVE-2008-0280" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in MTCMS 2.0 and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via the (1) a or (2) cid parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27224" source="BID">27224</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486090/100/0/threaded" source="BUGTRAQ">20080110 MTCMS &lt;=2.0 SQL Injection Vulnerbility</ref>
      <ref url="http://www.milw0rm.com/exploits/4882" source="MILW0RM">4882</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39597" source="XF">mtcms-a-sql-injection(39597)</ref>
      <ref url="http://securityreason.com/securityalert/3544" source="SREASON">3544</ref>
      <ref url="http://secunia.com/advisories/28428" source="SECUNIA">28428</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mtcms" name="mtcms">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0281" published="2008-01-15" name="CVE-2008-0281" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in liste.php in ID-Commerce 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idFamille parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39594" source="XF">idcommerce-liste-sql-injection(39594)</ref>
      <ref url="http://www.securityfocus.com/bid/27220" source="BID">27220</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059538.html" source="FULLDISC">20080110 ID-Commerce Security Advisory - SLR-2007-001</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059537.html" source="FULLDISC">20080110 (( PoC)) ID-Commerce Security Advisory - SLR-2007-001 (( PoC))</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059533.html" source="FULLDISC">20080110 ID-Commerce Security Advisory - SLR-2007-001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="id-commerce" name="id-commerce">
        <vers prev="1" num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0282" published="2008-01-15" name="CVE-2008-0282" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in welcome/inscription.php in DomPHP 0.81 and earlier allows remote attackers to execute arbitrary SQL commands via the mail parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39593" source="XF">domphp-inscription-sql-injection(39593)</ref>
      <ref url="http://www.securityfocus.com/bid/27212" source="BID">27212</ref>
      <ref url="http://www.milw0rm.com/exploits/4880" source="MILW0RM">4880</ref>
      <ref url="http://secunia.com/advisories/28393" source="SECUNIA" adv="1">28393</ref>
    </refs>
    <vuln_soft>
      <prod vendor="domphp" name="domphp">
        <vers prev="1" num="0.81"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0283" published="2008-01-15" name="CVE-2008-0283" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in /aides/index.php in DomPHP 0.81 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27226" source="BID">27226</ref>
      <ref url="http://www.milw0rm.com/exploits/4883" source="MILW0RM">4883</ref>
    </refs>
    <vuln_soft>
      <prod vendor="domphp" name="domphp">
        <vers prev="1" num="0.81"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0284" published="2008-01-15" name="CVE-2008-0284" modified="2009-09-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) Itemid or (2) topic arguments.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39585" source="XF">simplemachinesforum-itemid-xss(39585)</ref>
      <ref url="http://www.securityfocus.com/bid/27218" source="BID">27218</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486074/100/0/threaded" source="BUGTRAQ">20080110 Simple Machines Forum Cross-Site Scripting Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/3540" source="SREASON">3540</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simple_machines" name="simple_machines_smf">
        <vers prev="1" num="1.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0285" published="2008-01-15" name="CVE-2008-0285" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ngIRCd 0.10.x before 0.10.4 and 0.11.0 before 0.11.0-pre2 allows remote attackers to cause a denial of service (crash) via crafted IRC PART message, which triggers an invalid dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://ngircd.barton.de/doc/ChangeLog" source="CONFIRM">http://ngircd.barton.de/doc/ChangeLog</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=204834" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=204834</ref>
      <ref url="http://arthur.barton.de/cgi-bin/viewcvs.cgi/ngircd/ngircd/src/ngircd/irc-channel.c?r1=1.40&amp;r2=1.41&amp;diff_format=h" source="MISC">http://arthur.barton.de/cgi-bin/viewcvs.cgi/ngircd/ngircd/src/ngircd/irc-channel.c?r1=1.40&amp;r2=1.41&amp;diff_format=h</ref>
      <ref url="http://www.securityfocus.com/bid/27318" source="BID">27318</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200801-13.xml" source="GENTOO">GLSA-200801-13</ref>
      <ref url="http://secunia.com/advisories/28673" source="SECUNIA">28673</ref>
      <ref url="http://secunia.com/advisories/28425" source="SECUNIA">28425</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ngircd" name="ngircd">
        <vers prev="1" num="0.10.3"/>
        <vers prev="1" num="0.11.0-pre1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0286" published="2008-01-15" name="CVE-2008-0286" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in admin/login.php in Article Dashboard allows remote attackers to execute arbitrary SQL commands via the (1) user or (2) password fields.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27286" source="BID">27286</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486323/100/0/threaded" source="BUGTRAQ">20080115 Article DashBoard all version SQL Injection Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39657" source="XF">articledashboard-login-sql-injection(39657)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486646/100/0/threaded" source="BUGTRAQ">20080116 Re: Article DashBoard all version SQL Injection Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/3546" source="SREASON">3546</ref>
      <ref url="http://secunia.com/advisories/28495" source="SECUNIA">28495</ref>
    </refs>
    <vuln_soft>
      <prod vendor="article_dashboard" name="article_dashboard">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0287" published="2008-01-15" name="CVE-2008-0287" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in VisionBurst vcart 3.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php and (2) checkout.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39616" source="XF">vcart-checkout-index-file-include(39616)</ref>
      <ref url="http://www.securityfocus.com/bid/27231" source="BID">27231</ref>
      <ref url="http://www.milw0rm.com/exploits/4889" source="MILW0RM">4889</ref>
      <ref url="http://secunia.com/advisories/28424" source="SECUNIA" adv="1">28424</ref>
    </refs>
    <vuln_soft>
      <prod vendor="visionburst" name="vcart">
        <vers num="3.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0288" published="2008-01-15" name="CVE-2008-0288" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in ImageAlbum 2.0.0b2 allow remote attackers to execute arbitrary SQL commands via the id, which is not properly handled in (1) classes/IADomain.php, (2) classes/IACollection.php, and (3) classes/IAUser.php, as demonstrated via the id parameter in a collection.imageview action.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27240" source="BID">27240</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486162/100/0/threaded" source="BUGTRAQ">20080111 ImageAlbum Remote SQL Injection Vulnerabilities</ref>
      <ref url="http://www.milw0rm.com/exploits/4895" source="MILW0RM">4895</ref>
      <ref url="http://securityreason.com/securityalert/3548" source="SREASON">3548</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imagealbum" name="imagealbum">
        <vers num="2.0.0b2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0289" published="2008-01-15" name="CVE-2008-0289" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in view_func.php in Member Area System (MAS) 1.7 and possibly others allows remote attackers to execute arbitrary PHP code via a URL in the i parameter.  NOTE: a second vector might exist via the l parameter.  NOTE: as of 20080118, the vendor has disputed the set of affected versions, stating that the issue "is already fixed, for almost a year."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39611" source="XF">mas-viewfunc-file-include(39611)</ref>
      <ref url="http://www.securityfocus.com/bid/27244" source="BID">27244</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486618/100/0/threaded" source="BUGTRAQ">20080118 Re: Member Area System (MAS) Remote File Include Vulnerability (view_func.php)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486172/100/0/threaded" source="BUGTRAQ">20080111 Member Area System (MAS) Remote File Include Vulnerability (view_func.php)</ref>
      <ref url="http://securityreason.com/securityalert/3547" source="SREASON">3547</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mansion_productions" name="member_area_system">
        <vers prev="1" num="1.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0290" published="2008-01-15" name="CVE-2008-0290" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Digital Hive 2.0 RC2 and earlier allow (1) remote attackers to execute arbitrary SQL commands via the selectskin parameter to an unspecified program, or (2) remote authenticated administrators to execute arbitrary SQL commands via the user_id parameter in the gestion_membre.php page to base.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39602" source="XF">digitalhive-base-sql-injection(39602)</ref>
      <ref url="http://www.securityfocus.com/bid/27232" source="BID">27232</ref>
      <ref url="http://www.milw0rm.com/exploits/4887" source="MILW0RM">4887</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digitalhive" name="digitalhive">
        <vers prev="1" num="2.0_rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0291" published="2008-01-16" name="CVE-2008-0291" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in showproduct.asp in RichStrong CMS allows remote attackers to execute arbitrary SQL commands via the cat parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27281" source="BID">27281</ref>
      <ref url="http://www.milw0rm.com/exploits/4910" source="MILW0RM">4910</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39668" source="XF">richstrongcms-showproduct-sql-injection(39668)</ref>
      <ref url="http://www.securityfocus.com/bid/27310" source="BID">27310</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486402/100/0/threaded" source="BUGTRAQ">20080116 RichStrong CMS (showproduct.asp?cat=) Remote SQL Injection Exploit</ref>
      <ref url="http://secunia.com/advisories/28449" source="SECUNIA">28449</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hangzhou_rui-qiang" name="richstrong_cms">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0292" published="2008-01-16" name="CVE-2008-0292" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in photo_album.pl in Dansie Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39664" source="XF">dansiephotoalbum-photoalbum-xss(39664)</ref>
      <ref url="http://secunia.com/advisories/28501" source="SECUNIA">28501</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dansie" name="photo_album">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0293" published="2008-01-16" name="CVE-2008-0293" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in cron.php in FreeSeat before 1.1.5d, when format.php has certain modifications, allows remote attackers to bypass authentication and gain privileges via unspecified vectors related to the show_foot function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39648" source="XF">freeseat-cron-security-bypass(39648)</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=160239&amp;release_id=568374" source="CONFIRM">http://sourceforge.net/project/shownotes.php?group_id=160239&amp;release_id=568374</ref>
      <ref url="http://secunia.com/advisories/28459" source="SECUNIA" adv="1">28459</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freeseat" name="freeseat">
        <vers prev="1" num="1.1.5c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0294" published="2008-01-16" name="CVE-2008-0294" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the seat-locking implementation in FreeSeat before 1.1.5d allows attackers to book a seat more than once via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39647" source="XF">freeseat-seatlocking-security-bypass(39647)</ref>
      <ref url="http://www.securityfocus.com/bid/27270" source="BID">27270</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=568374&amp;group_id=160239" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=568374&amp;group_id=160239</ref>
      <ref url="http://secunia.com/advisories/28459" source="SECUNIA" adv="1">28459</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freeseat" name="freeseat">
        <vers prev="1" num="1.1.5c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0295" published="2008-01-16" name="CVE-2008-0295" modified="2012-01-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in modules/access/rtsp/real_sdpplin.c in the Xine library, as used in VideoLAN VLC Media Player 0.8.6d and earlier, allows user-assisted remote attackers to cause a denial of service (crash) or execute arbitrary code via long Session Description Protocol (SDP) data.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0105" source="VUPEN">ADV-2008-0105</ref>
      <ref url="http://www.securityfocus.com/bid/27221" source="BID">27221</ref>
      <ref url="http://secunia.com/advisories/28383" source="SECUNIA" adv="1">28383</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14776" source="OVAL">oval:org.mitre.oval:def:14776</ref>
      <ref url="http://aluigi.altervista.org/adv/vlcxhof-adv.txt" source="MISC">http://aluigi.altervista.org/adv/vlcxhof-adv.txt</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200803-13.xml" source="GENTOO">GLSA-200803-13</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1543" source="DEBIAN">DSA-1543</ref>
      <ref url="http://secunia.com/advisories/29766" source="SECUNIA">29766</ref>
      <ref url="http://secunia.com/advisories/29284" source="SECUNIA">29284</ref>
    </refs>
    <vuln_soft>
      <prod vendor="videolan" name="vlc_media_player">
        <vers prev="1" num="0.8.6d"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0296" published="2008-01-16" name="CVE-2008-0296" modified="2012-01-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the libaccess_realrtsp plugin in VideoLAN VLC Media Player 0.8.6d and earlier on Windows might allow remote RTSP servers to cause a denial of service (application crash) or execute arbitrary code via a long string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0105" source="VUPEN">ADV-2008-0105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14597" source="OVAL">oval:org.mitre.oval:def:14597</ref>
      <ref url="http://aluigi.altervista.org/adv/vlcxhof-adv.txt" source="MISC">http://aluigi.altervista.org/adv/vlcxhof-adv.txt</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200803-13.xml" source="GENTOO">GLSA-200803-13</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1543" source="DEBIAN">DSA-1543</ref>
      <ref url="http://secunia.com/advisories/29766" source="SECUNIA">29766</ref>
      <ref url="http://secunia.com/advisories/29284" source="SECUNIA">29284</ref>
    </refs>
    <vuln_soft>
      <prod vendor="videolan" name="vlc_media_player">
        <vers prev="1" num="0.8.6d"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0297" published="2008-01-16" name="CVE-2008-0297" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PhotoKorn allows remote attackers to obtain database credentials via a direct request to update/update3.php, which includes the credentials in its output.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39652" source="XF">photokorn-update3-information-disclosure(39652)</ref>
      <ref url="http://www.milw0rm.com/exploits/4897" source="MILW0RM">4897</ref>
    </refs>
    <vuln_soft>
      <prod vendor="keil_software" name="photokorn">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0298" published="2008-01-16" name="CVE-2008-0298" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">KHTML WebKit as used in Apple Safari 2.x allows remote attackers to cause a denial of service (browser crash) via a crafted web page, possibly involving a STYLE attribute of a DIV element.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39635" source="XF" patch="1">safari-khtml-webkit-dos(39635)</ref>
      <ref url="http://www.securityfocus.com/bid/27261" source="BID">27261</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486202/100/0/threaded" source="BUGTRAQ">20080112 Safari 2 Denial of Service</ref>
      <ref url="http://www.s21sec.com/avisos/s21sec-039-en.txt" source="MISC">http://www.s21sec.com/avisos/s21sec-039-en.txt</ref>
      <ref url="http://securityreason.com/securityalert/3549" source="SREASON">3549</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0299" published="2008-01-16" name="CVE-2008-0299" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=428727" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=428727</ref>
      <ref url="http://people.debian.org/~nion/nmu-diff/paramiko-1.6.4-1_1.6.4-1.1.patch" source="MISC">http://people.debian.org/~nion/nmu-diff/paramiko-1.6.4-1_1.6.4-1.1.patch</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=460706" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=460706</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00594.html" source="FEDORA">FEDORA-2008-0722</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00529.html" source="FEDORA">FEDORA-2008-0644</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39749" source="XF">paramiko-randompool-info-disclosure(39749)</ref>
      <ref url="http://www.securityfocus.com/bid/27307" source="BID">27307</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200803-07.xml" source="GENTOO">GLSA-200803-07</ref>
      <ref url="http://secunia.com/advisories/29168" source="SECUNIA">29168</ref>
      <ref url="http://secunia.com/advisories/28510" source="SECUNIA">28510</ref>
      <ref url="http://secunia.com/advisories/28488" source="SECUNIA">28488</ref>
    </refs>
    <vuln_soft>
      <prod vendor="python_software_foundation" name="paramiko">
        <vers num="1.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0300" published="2008-03-11" name="CVE-2008-0300" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">mapFiler.php in Mapbender 2.4 to 2.4.4 allows remote attackers to execute arbitrary PHP code via PHP code sequences in the factor parameter, which are not properly handled when accessing a filename that contains those sequences.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/28195" source="BID" patch="1">28195</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41131" source="XF">mapbender-mapfilter-code-execution(41131)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41131" source="XF">mapbender-mapfiler-code-execution(41131)</ref>
      <ref url="http://www.redteam-pentesting.de/advisories/rt-sa-2008-001.php" source="MISC">http://www.redteam-pentesting.de/advisories/rt-sa-2008-001.php</ref>
      <ref url="http://www.milw0rm.com/exploits/5232" source="MILW0RM">5232</ref>
      <ref url="http://secunia.com/advisories/29329" source="SECUNIA">29329</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mapbender" name="mapbender">
        <vers num="2.4"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0301" published="2008-03-11" name="CVE-2008-0301" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Mapbender 2.4.4 allow remote attackers to execute arbitrary SQL commands via the gaz parameter to mod_gazetteer_edit.php and other unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/41139" source="XF">mapbender-gaz-sql-injection(41139)</ref>
      <ref url="http://www.securityfocus.com/bid/28193" source="BID">28193</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/489383/100/0/threaded" source="BUGTRAQ">20080311 Advisory: SQL-Injections in Mapbender</ref>
      <ref url="http://www.redteam-pentesting.de/advisories/rt-sa-2008-002.php" source="MISC">http://www.redteam-pentesting.de/advisories/rt-sa-2008-002.php</ref>
      <ref url="http://www.milw0rm.com/exploits/5233" source="MILW0RM">5233</ref>
      <ref url="http://securityreason.com/securityalert/3728" source="SREASON">3728</ref>
      <ref url="http://secunia.com/advisories/29329" source="SECUNIA" adv="1">29329</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=120523564611595&amp;w=2" source="FULLDISC">20080311 Advisory: SQL-Injections in Mapbender</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mapbender" name="mapbender">
        <vers num="2.4"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0302" published="2008-01-16" name="CVE-2008-0302" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in apt-listchanges.py in apt-listchanges before 2.82 allows local users to execute arbitrary code via a malicious apt-listchanges program in the current working directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://packages.debian.org/changelogs/pool/main/a/apt-listchanges/apt-listchanges_2.82/changelog" source="CONFIRM">http://packages.debian.org/changelogs/pool/main/a/apt-listchanges/apt-listchanges_2.82/changelog</ref>
      <ref url="http://git.madism.org/?p=apt-listchanges.git;a=commitdiff;h=1bcfbf3dc55413bb83a1782dc9a54515a963fb32" source="CONFIRM">http://git.madism.org/?p=apt-listchanges.git;a=commitdiff;h=1bcfbf3dc55413bb83a1782dc9a54515a963fb32</ref>
      <ref url="http://www.ubuntu.com/usn/usn-572-1" source="UBUNTU">USN-572-1</ref>
      <ref url="http://www.securityfocus.com/bid/27331" source="BID">27331</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1465" source="DEBIAN">DSA-1465</ref>
      <ref url="http://secunia.com/advisories/28574" source="SECUNIA">28574</ref>
      <ref url="http://secunia.com/advisories/28513" source="SECUNIA">28513</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="apt-listchanges">
        <vers prev="1" num="2.81"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0303" published="2008-02-28" name="CVE-2008-0303" modified="2009-03-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The FTP print feature in multiple Canon printers, including imageRUNNER and imagePRESS, allow remote attackers to use the server as an inadvertent proxy via a modified PORT command, aka FTP bounce.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/568073" source="CERT-VN">VU#568073</ref>
      <ref url="http://www.usa.canon.com/html/security/pdf/CVA-001.pdf" source="CONFIRM">http://www.usa.canon.com/html/security/pdf/CVA-001.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/28042" source="BID">28042</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000013.html" source="JVNDB">JVNDB-2008-000013</ref>
      <ref url="http://jvn.jp/en/jp/JVN10056705/index.html" source="JVN">JVN#10056705</ref>
      <ref url="http://itso.iu.edu/20080229_Canon_MFD_FTP_bounce_attack" source="MISC">http://itso.iu.edu/20080229_Canon_MFD_FTP_bounce_attack</ref>
      <ref url="http://securitytracker.com/id?1019528" source="SECTRACK">1019528</ref>
    </refs>
    <vuln_soft>
      <prod vendor="canon" name="i-sensys">
        <vers num="lbp3360"/>
        <vers num="lbp3460"/>
        <vers num="lbp5360"/>
      </prod>
      <prod vendor="canon" name="imagepress">
        <vers num="c1"/>
      </prod>
      <prod vendor="canon" name="imagerunner">
        <vers num="105plus"/>
        <vers num="2230"/>
        <vers num="2270"/>
        <vers num="2570c"/>
        <vers num="2570ci"/>
        <vers num="2870"/>
        <vers num="3025"/>
        <vers num="3025n"/>
        <vers num="3035"/>
        <vers num="3035n"/>
        <vers num="3045"/>
        <vers num="3045n"/>
        <vers num="3170c"/>
        <vers num="3170ci"/>
        <vers num="3180c"/>
        <vers num="3180ci"/>
        <vers num="3530"/>
        <vers num="3570"/>
        <vers num="4570"/>
        <vers num="5055"/>
        <vers num="5055n"/>
        <vers num="5065"/>
        <vers num="5065n"/>
        <vers num="5075"/>
        <vers num="5075n"/>
        <vers num="5570"/>
        <vers num="5800c"/>
        <vers num="5800cn"/>
        <vers num="6570"/>
        <vers num="6800c"/>
        <vers num="6800cn"/>
        <vers num="7086"/>
        <vers num="7095"/>
        <vers num="7095p"/>
        <vers num="7105"/>
        <vers num="8070"/>
        <vers num="85plus"/>
        <vers num="c2380i"/>
        <vers num="c2620"/>
        <vers num="c2620n"/>
        <vers num="c2880"/>
        <vers num="c2880i"/>
        <vers num="c3220n"/>
        <vers num="c3380"/>
        <vers num="c3380i"/>
        <vers num="c4080i"/>
        <vers num="c4580i"/>
        <vers num="c5185i"/>
        <vers num="c5870"/>
        <vers num="c5870i"/>
        <vers num="c5880"/>
        <vers num="c5880i"/>
        <vers num="c6870i"/>
        <vers num="c6880"/>
        <vers num="c6880i"/>
        <vers num="clc4040"/>
        <vers num="clc5151"/>
      </prod>
      <prod vendor="canon" name="imagerunner_2620">
        <vers num=""/>
      </prod>
      <prod vendor="canon" name="imagerunner_5000i">
        <vers num=""/>
      </prod>
      <prod vendor="canon" name="imagerunner_5020">
        <vers num=""/>
      </prod>
      <prod vendor="canon" name="imagerunner_6870">
        <vers num=""/>
      </prod>
      <prod vendor="canon" name="imagerunner_8500">
        <vers num=""/>
      </prod>
      <prod vendor="canon" name="imagerunner_9070">
        <vers num=""/>
      </prod>
      <prod vendor="canon" name="imagerunner_c3200">
        <vers num=""/>
      </prod>
      <prod vendor="canon" name="imagerunner_c3220">
        <vers num=""/>
      </prod>
      <prod vendor="canon" name="imagerunner_c6800">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0304" published="2008-02-29" name="CVE-2008-0304" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.12 and SeaMonkey before 1.1.8 might allow remote attackers to execute arbitrary code via a crafted external-body MIME type in an e-mail message, related to an incorrect memory allocation during message preview.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/661651" source="CERT-VN">VU#661651</ref>
      <ref url="http://www.securityfocus.com/bid/28012" source="BID" patch="1">28012</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/2091/references" source="VUPEN">ADV-2008-2091</ref>
      <ref url="http://www.mozilla.org/security/announce/2008/mfsa2008-12.html" source="CONFIRM">http://www.mozilla.org/security/announce/2008/mfsa2008-12.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml" source="GENTOO">GLSA-200805-18</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1697" source="DEBIAN">DSA-1697</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1621" source="DEBIAN">DSA-1621</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-239546-1" source="SUNALERT">239546</ref>
      <ref url="http://securitytracker.com/id?1019504" source="SECTRACK">1019504</ref>
      <ref url="http://secunia.com/advisories/33433" source="SECUNIA">33433</ref>
      <ref url="http://secunia.com/advisories/31253" source="SECUNIA">31253</ref>
      <ref url="http://secunia.com/advisories/31043" source="SECUNIA">31043</ref>
      <ref url="http://secunia.com/advisories/29133" source="SECUNIA" adv="1">29133</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11075" source="OVAL">oval:org.mitre.oval:def:11075</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=668" source="IDEFENSE">20080226 Mozilla Thunderbird MIME External-Body Heap Overflow Vulnerability</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.html" source="FEDORA">FEDORA-2008-2118</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.html" source="FEDORA">FEDORA-2008-2060</ref>
      <ref url="http://www.ubuntu.com/usn/usn-582-2" source="UBUNTU">USN-582-2</ref>
      <ref url="http://www.ubuntu.com/usn/usn-582-1" source="UBUNTU">USN-582-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:062" source="MANDRIVA">MDVSA-2008:062</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2008&amp;m=slackware-security.445399" source="SLACKWARE">SSA:2008-061-01</ref>
      <ref url="http://secunia.com/advisories/30327" source="SECUNIA">30327</ref>
      <ref url="http://secunia.com/advisories/29211" source="SECUNIA">29211</ref>
      <ref url="http://secunia.com/advisories/29167" source="SECUNIA">29167</ref>
      <ref url="http://secunia.com/advisories/29098" source="SECUNIA">29098</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.1.7"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers prev="1" num="2.0.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0306" published="2008-03-11" name="CVE-2008-0306" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">sdbstarter in SAP MaxDB 7.6.0.37, and possibly other versions, allows local users to execute arbitrary commands by using unspecified environment variables to modify configuration settings.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/41104" source="XF">maxdb-sdbstarter-privilege-escalation(41104)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0844/references" source="VUPEN">ADV-2008-0844</ref>
      <ref url="http://www.securitytracker.com/id?1019570" source="SECTRACK">1019570</ref>
      <ref url="http://www.securityfocus.com/bid/28185" source="BID">28185</ref>
      <ref url="http://secunia.com/advisories/29312" source="SECUNIA" adv="1">29312</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=670" source="IDEFENSE">20080310 SAP MaxDB sdbstarter Privilege Escalation Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="maxdb">
        <vers num="7.6.0.37"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0307" published="2008-03-11" name="CVE-2008-0307" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer signedness error in vserver in SAP MaxDB 7.6.0.37, and possibly other versions, allows remote attackers to execute arbitrary code via unknown vectors that trigger heap corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/41107" source="XF">maxdb-vserver-code-execution(41107)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0844/references" source="VUPEN">ADV-2008-0844</ref>
      <ref url="http://www.securitytracker.com/id?1019571" source="SECTRACK">1019571</ref>
      <ref url="http://www.securityfocus.com/bid/28183" source="BID">28183</ref>
      <ref url="http://secunia.com/advisories/29312" source="SECUNIA" adv="1">29312</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=669" source="IDEFENSE">20080310 SAP MaxDB Signedness Error Heap Corruption Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="maxdb">
        <vers num="7.6.0.37"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0308" published="2008-02-28" name="CVE-2008-0308" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to cause a denial of service (memory consumption) via a malformed RAR file to the Internet Content Adaptation Protocol (ICAP) port (1344/tcp).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0680" source="VUPEN">ADV-2008-0680</ref>
      <ref url="http://www.symantec.com/avcenter/security/Content/2008.02.27.html" source="CONFIRM">http://www.symantec.com/avcenter/security/Content/2008.02.27.html</ref>
      <ref url="http://www.securitytracker.com/id?1019503" source="SECTRACK">1019503</ref>
      <ref url="http://www.securityfocus.com/bid/27911" source="BID">27911</ref>
      <ref url="http://secunia.com/advisories/29140" source="SECUNIA" adv="1">29140</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=666" source="IDEFENSE">20080226 Symantec Scan Engine 5.1.2 RAR File Denial of Service Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="scan_engine">
        <vers prev="1" num="5.1.4.24"/>
      </prod>
      <prod vendor="symantec" name="symantec_antivirus_clearswift">
        <vers prev="1" num="4.3.16.39"/>
      </prod>
      <prod vendor="symantec" name="symantec_antivirus_filtering_domino_mpe">
        <vers prev="1" num="3.0.12" edition=""/>
        <vers prev="1" num="3.0.12" edition=":linux"/>
        <vers prev="1" num="3.0.12" edition=":solaris"/>
        <vers prev="1" num="3.0.12" edition=":aix"/>
      </prod>
      <prod vendor="symantec" name="symantec_antivirus_messaging">
        <vers prev="1" num="4.3.16.39"/>
      </prod>
      <prod vendor="symantec" name="symantec_antivirus_microsoft_sharepoint">
        <vers prev="1" num="4.3.16.39"/>
      </prod>
      <prod vendor="symantec" name="symantec_antivirus_ms_isa">
        <vers prev="1" num="4.3.16.39"/>
      </prod>
      <prod vendor="symantec" name="symantec_antivirus_network_attached_storage">
        <vers prev="1" num="4.3.16.39"/>
      </prod>
      <prod vendor="symantec" name="symantec_antivirus_scan_engine">
        <vers prev="1" num="4.3.16.39"/>
      </prod>
      <prod vendor="symantec" name="symantec_antivirus_scan_engine_caching">
        <vers prev="1" num="4.3.16.39"/>
      </prod>
      <prod vendor="symantec" name="symantec_mail_security_exchange">
        <vers prev="1" num="4.6.5.12"/>
        <vers prev="1" num="5.0.4.363"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0309" published="2008-02-28" name="CVE-2008-0309" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed RAR file to the Internet Content Adaptation Protocol (ICAP) port (1344/tcp).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0680" source="VUPEN">ADV-2008-0680</ref>
      <ref url="http://www.symantec.com/avcenter/security/Content/2008.02.27.html" source="CONFIRM">http://www.symantec.com/avcenter/security/Content/2008.02.27.html</ref>
      <ref url="http://www.securitytracker.com/id?1019503" source="SECTRACK">1019503</ref>
      <ref url="http://www.securityfocus.com/bid/27913" source="BID">27913</ref>
      <ref url="http://secunia.com/advisories/29140" source="SECUNIA" adv="1">29140</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=667" source="IDEFENSE">20080226 Symantec Scan Engine 5.1.2 RAR File Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="scan_engine">
        <vers prev="1" num="5.1.4.24"/>
      </prod>
      <prod vendor="symantec" name="symantec_antivirus_filtering_domino_mpe">
        <vers prev="1" num="3.0.12" edition=""/>
        <vers prev="1" num="3.0.12" edition=":linux"/>
        <vers prev="1" num="3.0.12" edition=":solaris"/>
        <vers prev="1" num="3.0.12" edition=":aix"/>
      </prod>
      <prod vendor="symantec" name="symantec_antivirus_network_attached_storage">
        <vers prev="1" num="4.3.16.39"/>
      </prod>
      <prod vendor="symantec" name="symantec_antivirus_scan_engine">
        <vers prev="1" num="4.3.16.39"/>
      </prod>
      <prod vendor="symantec" name="symantec_antivirus_scan_engine_caching">
        <vers prev="1" num="4.3.16.39"/>
      </prod>
      <prod vendor="symantec" name="symantec_antivirus_scan_engine_clearswift">
        <vers prev="1" num="4.3.16.39"/>
      </prod>
      <prod vendor="symantec" name="symantec_antivirus_scan_engine_for_microsoft_sharepoint">
        <vers prev="1" num="4.3.16.39"/>
      </prod>
      <prod vendor="symantec" name="symantec_antivirus_scan_engine_for_ms_isa">
        <vers prev="1" num="4.3.16.39"/>
      </prod>
      <prod vendor="symantec" name="symantec_antivirus_scan_engine_messaging">
        <vers prev="1" num="4.3.16.39"/>
      </prod>
      <prod vendor="symantec" name="symantec_mail_security_for_microsoft_exchange">
        <vers prev="1" num="4.6.5.12"/>
        <vers prev="1" num="5.0.4.363"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0310" published="2008-04-07" name="CVE-2008-0310" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Directory traversal vulnerability in pkgadd in SCO UnixWare 7.1.4 before p534589 allows local users to create or append to arbitrary files via ".." sequences in an unspecified environment variable, probably PKGINST.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.sco.com/support/update/download/release.php?rid=324" source="CONFIRM" patch="1" adv="1">http://www.sco.com/support/update/download/release.php?rid=324</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41759" source="XF">sco-unixware-pkgadd-directory-traversal(41759)</ref>
      <ref url="http://www.securitytracker.com/id?1019787" source="SECTRACK">1019787</ref>
      <ref url="http://www.milw0rm.com/exploits/5355" source="MILW0RM">5355</ref>
      <ref url="http://secunia.com/advisories/29657" source="SECUNIA" adv="1">29657</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=676" source="IDEFENSE">20080403 SCO UnixWare pkgadd Directory Traversal Vulnerability</ref>
      <ref url="http://ftp.sco.com/pub/unixware7/714/security/p534589/p534589.txt" source="SCO">SCOSA-2008.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers num="7.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0311" published="2008-04-06" name="CVE-2008-0311" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the PGMWebHandler::parse_request function in the StarTeam Multicast Service component (STMulticastService) 6.4 in Borland CaliberRM 2006 allows remote attackers to execute arbitrary code via a large HTTP request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/1100" source="VUPEN">ADV-2008-1100</ref>
      <ref url="http://www.securityfocus.com/bid/28602" source="BID">28602</ref>
      <ref url="http://securitytracker.com/id?1019786" source="SECTRACK">1019786</ref>
      <ref url="http://secunia.com/advisories/29631" source="SECUNIA" adv="1">29631</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=675" source="IDEFENSE">20080402 Borland CaliberRM StarTeam Multicast Service Buffer Overflow Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41647" source="XF">starteam-pgmwebhandlerparserequest-bo(41647)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="borland" name="caliberrm">
        <vers num="2006"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0312" published="2008-04-08" name="CVE-2008-0312" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the AutoFix Support Tool ActiveX control 2.7.0.1 in SYMADATA.DLL in multiple Symantec Norton products, including Norton 360 1.0, AntiVirus 2006 through 2008, Internet Security 2006 through 2008, and System Works 2006 through 2008, allows remote attackers to execute arbitrary code via a long argument to the GetEventLogInfo method.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1019753" source="SECTRACK" patch="1">1019753</ref>
      <ref url="http://www.securitytracker.com/id?1019752" source="SECTRACK" patch="1">1019752</ref>
      <ref url="http://www.securitytracker.com/id?1019751" source="SECTRACK" patch="1">1019751</ref>
      <ref url="http://www.securityfocus.com/bid/28507" source="BID" patch="1">28507</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2008.04.02a.html" source="CONFIRM" patch="1">http://securityresponse.symantec.com/avcenter/security/Content/2008.04.02a.html</ref>
      <ref url="http://secunia.com/advisories/29660" source="SECUNIA" patch="1" adv="1">29660</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41629" source="XF">symantec-autofixtool-bo(41629)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1077/references" source="VUPEN">ADV-2008-1077</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=677" source="IDEFENSE">20080402 Symantec Norton Internet Security 2008 ActiveX Control Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_360">
        <vers num="1.0"/>
      </prod>
      <prod vendor="symantec" name="norton_antivirus">
        <vers num="2006"/>
        <vers num="2007"/>
        <vers num="2008"/>
      </prod>
      <prod vendor="symantec" name="norton_internet_security">
        <vers num="2006"/>
        <vers num="2007"/>
        <vers num="2008"/>
      </prod>
      <prod vendor="symantec" name="norton_system_works">
        <vers num="2006"/>
        <vers num="2007"/>
        <vers num="2008"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0313" published="2008-04-08" name="CVE-2008-0313" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The ActiveDataInfo.LaunchProcess method in the SymAData.ActiveDataInfo.1 ActiveX control 2.7.0.1 in SYMADATA.DLL in multiple Symantec Norton products including Norton 360 1.0, AntiVirus 2006 through 2008, Internet Security 2006 through 2008, and System Works 2006 through 2008, does not properly determine the location of the AutoFix Tool, which allows remote attackers to execute arbitrary code via a remote (1) WebDAV or (2) SMB share.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/28509" source="BID" patch="1">28509</ref>
      <ref url="http://secunia.com/advisories/29660" source="SECUNIA" patch="1" adv="1">29660</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41631" source="XF">symantec-autofixtool-code-execution(41631)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1077/references" source="VUPEN">ADV-2008-1077</ref>
      <ref url="http://www.securitytracker.com/id?1019753" source="SECTRACK">1019753</ref>
      <ref url="http://www.securitytracker.com/id?1019752" source="SECTRACK">1019752</ref>
      <ref url="http://www.securitytracker.com/id?1019751" source="SECTRACK">1019751</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2008.04.02a.html" source="CONFIRM">http://securityresponse.symantec.com/avcenter/security/Content/2008.04.02a.html</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=678" source="IDEFENSE">20080402 Symantec Internet Security 2008 ActiveDataInfo.LaunchProcess Design Error Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_360">
        <vers num="1.0"/>
      </prod>
      <prod vendor="symantec" name="norton_antivirus">
        <vers num="2006"/>
        <vers num="2007"/>
        <vers num="2008"/>
      </prod>
      <prod vendor="symantec" name="norton_internet_security">
        <vers num="2006"/>
        <vers num="2007"/>
        <vers num="2008"/>
      </prod>
      <prod vendor="symantec" name="system_works">
        <vers num="2006"/>
        <vers num="2007"/>
        <vers num="2008"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0314" published="2008-04-16" name="CVE-2008-0314" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in spin.c in libclamav in ClamAV 0.92.1 allows remote attackers to execute arbitrary code via a crafted PeSpin packed PE binary with a modified length value.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-260A.html" source="CERT">TA08-260A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858595" source="CERT-VN">VU#858595</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/2584" source="VUPEN">ADV-2008-2584</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1227/references" source="VUPEN">ADV-2008-1227</ref>
      <ref url="http://up2date.astaro.com/2008/08/up2date_asg_v7300_ga_released.html" source="CONFIRM">http://up2date.astaro.com/2008/08/up2date_asg_v7300_ga_released.html</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200805-19.xml" source="GENTOO">GLSA-200805-19</ref>
      <ref url="http://secunia.com/advisories/31882" source="SECUNIA">31882</ref>
      <ref url="http://secunia.com/advisories/31576" source="SECUNIA">31576</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2008/Sep/msg00005.html" source="APPLE">APPLE-SA-2008-09-15</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=686" source="IDEFENSE">20080414 ClamAV libclamav PeSpin Heap Overflow Vulnerability</ref>
      <ref url="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=876" source="CONFIRM">https://wwws.clamav.net/bugzilla/show_bug.cgi?id=876</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00249.html" source="FEDORA">FEDORA-2008-3900</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00625.html" source="FEDORA">FEDORA-2008-3420</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00576.html" source="FEDORA">FEDORA-2008-3358</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41823" source="XF">clamav-spin-bo(41823)</ref>
      <ref url="http://www.securitytracker.com/id?1019851" source="SECTRACK">1019851</ref>
      <ref url="http://www.securityfocus.com/bid/28784" source="BID">28784</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:088" source="MANDRIVA">MDVSA-2008:088</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1549" source="DEBIAN">DSA-1549</ref>
      <ref url="http://svn.clamav.net/svn/clamav-devel/trunk/ChangeLog" source="CONFIRM">http://svn.clamav.net/svn/clamav-devel/trunk/ChangeLog</ref>
      <ref url="http://secunia.com/advisories/30328" source="SECUNIA">30328</ref>
      <ref url="http://secunia.com/advisories/30253" source="SECUNIA">30253</ref>
      <ref url="http://secunia.com/advisories/29975" source="SECUNIA">29975</ref>
      <ref url="http://secunia.com/advisories/29891" source="SECUNIA">29891</ref>
      <ref url="http://secunia.com/advisories/29886" source="SECUNIA">29886</ref>
      <ref url="http://secunia.com/advisories/29863" source="SECUNIA">29863</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00009.html" source="SUSE">SUSE-SA:2008:024</ref>
      <ref url="http://kolab.org/security/kolab-vendor-notice-20.txt" source="CONFIRM">http://kolab.org/security/kolab-vendor-notice-20.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers num="0.92.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0318" published="2008-02-12" name="CVE-2008-0318" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in the cli_scanpe function in libclamav in ClamAV before 0.92.1, as used in clamd, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Petite packed PE file, which triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=575703" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=575703</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00481.html" source="FEDORA">FEDORA-2008-1625</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00462.html" source="FEDORA">FEDORA-2008-1608</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN" adv="1">ADV-2008-0924</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0606" source="VUPEN" adv="1">ADV-2008-0606</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0503" source="VUPEN" adv="1">ADV-2008-0503</ref>
      <ref url="http://www.securityfocus.com/bid/27751" source="BID">27751</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:088" source="MANDRIVA">MDVSA-2008:088</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1497" source="DEBIAN">DSA-1497</ref>
      <ref url="http://support.novell.com/techcenter/psdb/512985d2cd3090bfb93dcb7b551179cf.html" source="CONFIRM">http://support.novell.com/techcenter/psdb/512985d2cd3090bfb93dcb7b551179cf.html</ref>
      <ref url="http://securitytracker.com/id?1019394" source="SECTRACK">1019394</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200802-09.xml" source="GENTOO">GLSA-200802-09</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA" adv="1">29420</ref>
      <ref url="http://secunia.com/advisories/29060" source="SECUNIA" adv="1">29060</ref>
      <ref url="http://secunia.com/advisories/29048" source="SECUNIA" adv="1">29048</ref>
      <ref url="http://secunia.com/advisories/29026" source="SECUNIA" adv="1">29026</ref>
      <ref url="http://secunia.com/advisories/29001" source="SECUNIA" adv="1">29001</ref>
      <ref url="http://secunia.com/advisories/28949" source="SECUNIA" adv="1">28949</ref>
      <ref url="http://secunia.com/advisories/28913" source="SECUNIA" adv="1">28913</ref>
      <ref url="http://secunia.com/advisories/28907" source="SECUNIA" adv="1">28907</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00008.html" source="SUSE">SUSE-SR:2008:004</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE">APPLE-SA-2008-03-18</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=658" source="IDEFENSE">20080212 ClamAV libclamav PE File Integer Overflow Vulnerability</ref>
      <ref url="http://kolab.org/security/kolab-vendor-notice-19.txt" source="CONFIRM">http://kolab.org/security/kolab-vendor-notice-19.txt</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=209915" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=209915</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers prev="1" num="0.92"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0320" published="2008-04-17" name="CVE-2008-0320" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an OLE file with a crafted DocumentSummaryInformation stream.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00448.html" source="FEDORA">FEDORA-2008-3251</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41860" source="XF">openoffice-ole-bo(41860)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1375/references" source="VUPEN" adv="1">ADV-2008-1375</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1253/references" source="VUPEN" adv="1">ADV-2008-1253</ref>
      <ref url="http://www.ubuntu.com/usn/usn-609-1" source="UBUNTU">USN-609-1</ref>
      <ref url="http://www.securitytracker.com/id?1019890" source="SECTRACK">1019890</ref>
      <ref url="http://www.securityfocus.com/bid/28819" source="BID">28819</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0176.html" source="REDHAT" adv="1">RHSA-2008:0176</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0175.html" source="REDHAT">RHSA-2008:0175</ref>
      <ref url="http://www.openoffice.org/security/cves/CVE-2008-0320.html" source="CONFIRM">http://www.openoffice.org/security/cves/CVE-2008-0320.html</ref>
      <ref url="http://www.openoffice.org/security/cves/CVE-2007-5745.html" source="CONFIRM">http://www.openoffice.org/security/cves/CVE-2007-5745.html</ref>
      <ref url="http://www.openoffice.org/security/cves/CVE-2007-4770.html" source="CONFIRM">http://www.openoffice.org/security/cves/CVE-2007-4770.html</ref>
      <ref url="http://www.openoffice.org/security/bulletin.html" source="CONFIRM">http://www.openoffice.org/security/bulletin.html</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2008_23_openoffice.html" source="SUSE">SUSE-SA:2008:023</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:095" source="MANDRIVA">MDVSA-2008:095</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:090" source="MANDRIVA">MDVSA-2008:090</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1547" source="DEBIAN">DSA-1547</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-231642-1" source="SUNALERT">231642</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200805-16.xml" source="GENTOO">GLSA-200805-16</ref>
      <ref url="http://secunia.com/advisories/30179" source="SECUNIA" adv="1">30179</ref>
      <ref url="http://secunia.com/advisories/30100" source="SECUNIA" adv="1">30100</ref>
      <ref url="http://secunia.com/advisories/29987" source="SECUNIA" adv="1">29987</ref>
      <ref url="http://secunia.com/advisories/29913" source="SECUNIA" adv="1">29913</ref>
      <ref url="http://secunia.com/advisories/29910" source="SECUNIA" adv="1">29910</ref>
      <ref url="http://secunia.com/advisories/29871" source="SECUNIA" adv="1">29871</ref>
      <ref url="http://secunia.com/advisories/29864" source="SECUNIA" adv="1">29864</ref>
      <ref url="http://secunia.com/advisories/29852" source="SECUNIA" adv="1">29852</ref>
      <ref url="http://secunia.com/advisories/29844" source="SECUNIA" adv="1">29844</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10318" source="OVAL">oval:org.mitre.oval:def:10318</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=694" source="IDEFENSE">20080417 Multiple Vendor OpenOffice OLE DocumentSummaryInformation Heap Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openoffice" name="openoffice.org">
        <vers num="2.0.3"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.3"/>
        <vers prev="1" num="2.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0322" published="2008-05-13" name="CVE-2008-0322" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The I2O Utility Filter driver (i2omgmt.sys) 5.1.2600.2180 for Microsoft Windows XP sets Everyone/Write permissions for the "\\.\I2OExc" device interface, which allows local users to gain privileges.  NOTE: this issue can be leveraged to overwrite arbitrary memory and execute code via an IOCTL call with a crafted DeviceObject pointer.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/29171" source="BID" patch="1">29171</ref>
      <ref url="http://secunia.com/advisories/30203" source="SECUNIA" patch="1" adv="1">30203</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=699" source="IDEFENSE" patch="1">20080512 Microsoft Windows I2O Filter Utility Driver (i2omgmt.sys) Local Privilege Escalation Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/42358" source="XF">win-i2omgmt-code-execution(42358)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1476/references" source="VUPEN">ADV-2008-1476</ref>
      <ref url="http://www.securitytracker.com/id?1020006" source="SECTRACK">1020006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0324" published="2008-01-16" name="CVE-2008-0324" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Cisco Systems VPN Client IPSec Driver (CVPNDRVA.sys) 5.0.02.0090 allows local users to cause a denial of service (crash) by calling the 0x80002038 IOCTL with a small size value, which triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39694" source="XF">cisco-vpnclient-cvpndrva-dos(39694)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0170" source="VUPEN">ADV-2008-0170</ref>
      <ref url="http://www.securityfocus.com/bid/27289" source="BID">27289</ref>
      <ref url="http://www.milw0rm.com/exploits/4911" source="MILW0RM">4911</ref>
      <ref url="http://www.securitytracker.com/id?1019240" source="SECTRACK">1019240</ref>
      <ref url="http://secunia.com/advisories/28472" source="SECUNIA">28472</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="vpn_client">
        <vers num="5.0.2.0090" edition=""/>
        <vers num="5.0.2.0090" edition=":windows"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0325" published="2008-01-17" name="CVE-2008-0325" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in show.php in FaScript FaPersian Petition allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27302" source="BID">27302</ref>
      <ref url="http://www.milw0rm.com/exploits/4916" source="MILW0RM">4916</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39716" source="XF">fascriptfapersian-show-sql-injection(39716)</ref>
      <ref url="http://secunia.com/advisories/28522" source="SECUNIA">28522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fascript" name="fapersian_petition">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0326" published="2008-01-17" name="CVE-2008-0326" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in class/show.php in FaScript FaPersianHack 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to show.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27302" source="BID">27302</ref>
      <ref url="http://www.milw0rm.com/exploits/4917" source="MILW0RM">4917</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39717" source="XF">fascriptfapersianhack-show-sql-injection(39717)</ref>
      <ref url="http://secunia.com/advisories/28565" source="SECUNIA">28565</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fascript" name="fapersianhack">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0327" published="2008-01-17" name="CVE-2008-0327" modified="2009-09-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in show.php in FaScript FaMp3 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27302" source="BID">27302</ref>
      <ref url="http://www.milw0rm.com/exploits/4914" source="MILW0RM">4914</ref>
      <ref url="http://osvdb.org/40330" source="OSVDB">40330</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39714" source="XF">fascriptfamp3-show-sql-injection(39714)</ref>
      <ref url="http://secunia.com/advisories/28566" source="SECUNIA">28566</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fascript" name="famp3">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0328" published="2008-01-17" name="CVE-2008-0328" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in page.php in FaScript FaName 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27303" source="BID">27303</ref>
      <ref url="http://www.milw0rm.com/exploits/4915" source="MILW0RM">4915</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39715" source="XF">fascriptfaname-page-sql-injection(39715)</ref>
      <ref url="http://secunia.com/advisories/28528" source="SECUNIA">28528</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fascript" name="faname">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0329" published="2008-01-17" name="CVE-2008-0329" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">LulieBlog 1.0.1 and 1.0.2 does not restrict access to (1) article_suppr.php, (2) comment_accepter.php, and (3) comment_refuser.php in Admin/, which allows remote attackers to accept comments, delete comments, and delete articles via the id parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39669" source="XF">lulieblog-admin-security-bypass(39669)</ref>
      <ref url="http://www.securityfocus.com/bid/27290" source="BID">27290</ref>
      <ref url="http://www.milw0rm.com/exploits/4912" source="MILW0RM">4912</ref>
      <ref url="http://secunia.com/advisories/28432" source="SECUNIA" adv="1">28432</ref>
    </refs>
    <vuln_soft>
      <prod vendor="julien_plesniak" name="lulieblog">
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0330" published="2008-01-17" name="CVE-2008-0330" modified="2011-08-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Open System Consultants (OSC) Radiator before 4.0 allows remote attackers to cause a denial of service (daemon crash) via malformed RADIUS requests, as demonstrated by packets sent by nmap.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/40664" source="XF">osc-radiator-unspecified-dos(40664)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39730" source="XF">radiator-radius-dos(39730)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0598" source="VUPEN" adv="1">ADV-2008-0598</ref>
      <ref url="http://www.securityfocus.com/bid/27306" source="BID">27306</ref>
      <ref url="http://www.open.com.au/radiator/history.html" source="CONFIRM">http://www.open.com.au/radiator/history.html</ref>
      <ref url="http://secunia.com/advisories/28463" source="SECUNIA" adv="1">28463</ref>
    </refs>
    <vuln_soft>
      <prod vendor="radiator" name="radius_server">
        <vers prev="1" num="3.17.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0331" published="2008-01-17" name="CVE-2008-0331" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Funkwerk System Software before 7.4.1 PATCH 9 for certain Funkwerk Router / VPN devices allows remote attackers to cause a denial of service (panic and reboot) via unspecified DNS requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.funkwerk-ec.com/portal/downloadcenter/dateien/x2300/r7401p09/readme_741p9_en.pdf" source="CONFIRM">http://www.funkwerk-ec.com/portal/downloadcenter/dateien/x2300/r7401p09/readme_741p9_en.pdf</ref>
      <ref url="http://secunia.com/advisories/28085" source="SECUNIA" adv="1">28085</ref>
      <ref url="http://osvdb.org/42782" source="OSVDB">42782</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39731" source="XF">x2300-dns-dos(39731)</ref>
      <ref url="http://www.securityfocus.com/bid/27314" source="BID">27314</ref>
    </refs>
    <vuln_soft>
      <prod vendor="funkwerk" name="system_software">
        <vers prev="1" num="7.4.1_patch_8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0332" published="2008-01-17" name="CVE-2008-0332" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in arias/help/effect.php in aria 0.99-6 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/4920" source="MILW0RM">4920</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39712" source="XF">aria-effect-file-include(39712)</ref>
      <ref url="http://www.securityfocus.com/bid/27311" source="BID">27311</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486406/100/0/threaded" source="BUGTRAQ">20080116 [DSECRG-08-002] Local File Include in arias 0.99-6</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aria" name="aria">
        <vers num="0.99-6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0333" published="2008-01-17" name="CVE-2008-0333" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in download_view_attachment.aspx in AfterLogic MailBee WebMail Pro 4.1 for ASP.NET allows remote attackers to read arbitrary files via a .. (dot dot) in the temp_filename parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/4921" source="MILW0RM">4921</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39724" source="XF">mailbeewebmail-download-directory-traversal(39724)</ref>
      <ref url="http://www.securityfocus.com/bid/27312" source="BID">27312</ref>
      <ref url="http://secunia.com/advisories/28521" source="SECUNIA">28521</ref>
    </refs>
    <vuln_soft>
      <prod vendor="afterlogic" name="mailbee_webmail_pro">
        <vers num="4.1"/>
      </prod>
      <prod vendor="microsoft" name="asp.net">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2008-0334" published="2008-01-17" name="CVE-2008-0334" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in pm/language/spanish/preferences.php in PMachine Pro 2.4.1 allows remote attackers to inject arbitrary web script or HTML via the L_PREF_NAME[855] parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27282" source="BID">27282</ref>
      <ref url="http://packetstormsecurity.org/0801-exploits/pMachinePro-241-xss.txt" source="MISC">http://packetstormsecurity.org/0801-exploits/pMachinePro-241-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pmachine" name="pmachine_pro">
        <vers num="2.4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0335" published="2008-01-17" name="CVE-2008-0335" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in BugTracker.NET before 2.7.2 allows remote attackers to inject arbitrary web script or HTML via an arbitrary custom text field.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=568160" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=568160</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39650" source="XF">bugtrackernet-bug-xss(39650)</ref>
      <ref url="http://www.securityfocus.com/bid/27275" source="BID">27275</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1867089&amp;group_id=66812&amp;atid=515837" source="CONFIRM">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1867089&amp;group_id=66812&amp;atid=515837</ref>
      <ref url="http://secunia.com/advisories/28481" source="SECUNIA" adv="1">28481</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bugtracker.net" name="bugtracker.net">
        <vers prev="1" num="2.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0336" published="2008-01-17" name="CVE-2008-0336" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in BugTracker.NET before 2.7.2 allow remote attackers to delete arbitrary bugs and perform other administrative tasks via unspecified vectors, possibly related to delete_*.aspx pages, and massedit.aspx, subscribe.aspx, flag.aspx, and relationships.aspx.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=66812&amp;release_id=568160" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=66812&amp;release_id=568160</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39651" source="XF">bugtrackernet-http-csrf(39651)</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1867089&amp;group_id=66812&amp;atid=515837" source="CONFIRM">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1867089&amp;group_id=66812&amp;atid=515837</ref>
      <ref url="http://secunia.com/advisories/28481" source="SECUNIA" adv="1">28481</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bugtracker.net" name="bugtracker.net">
        <vers prev="1" num="2.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0337" published="2008-01-17" name="CVE-2008-0337" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the _mwProcessReadSocket function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to execute arbitrary code via a long URI.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0176" source="VUPEN">ADV-2008-0176</ref>
      <ref url="http://www.milw0rm.com/exploits/4923" source="MILW0RM">4923</ref>
      <ref url="http://www.bugtraq.ir/adv/miniweb_english.pdf" source="MISC">http://www.bugtraq.ir/adv/miniweb_english.pdf</ref>
      <ref url="http://secunia.com/advisories/28512" source="SECUNIA" adv="1">28512</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39718" source="XF">miniweb-mwprocessreadsocket-bo(39718)</ref>
      <ref url="http://www.securityfocus.com/bid/27319" source="BID">27319</ref>
    </refs>
    <vuln_soft>
      <prod vendor="miniweb_http_server" name="miniweb_http_server">
        <vers num="0.8.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0338" published="2008-01-17" name="CVE-2008-0338" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the mwGetLocalFileName function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to read arbitrary files and list arbitrary directories via a (1) .%2e (partially encoded dot dot) or (2) %2e%2e (encoded dot dot) in the URI.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0176" source="VUPEN">ADV-2008-0176</ref>
      <ref url="http://www.milw0rm.com/exploits/4923" source="MILW0RM">4923</ref>
      <ref url="http://www.bugtraq.ir/adv/miniweb_english.pdf" source="MISC">http://www.bugtraq.ir/adv/miniweb_english.pdf</ref>
      <ref url="http://secunia.com/advisories/28512" source="SECUNIA" adv="1">28512</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39713" source="XF">miniweb-mwgetlocal-directory-traversal(39713)</ref>
      <ref url="http://www.securityfocus.com/bid/27319" source="BID">27319</ref>
    </refs>
    <vuln_soft>
      <prod vendor="miniweb_http_server" name="miniweb_http_server">
        <vers num="0.8.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0339" published="2008-01-17" name="CVE-2008-0339" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 has unknown impact and remote attack vectors, aka DB01.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-017A.html" source="CERT" patch="1">TA08-017A</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2" source="HP" patch="1">SSRT061201</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0180" source="VUPEN">ADV-2008-0180</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0150" source="VUPEN">ADV-2008-0150</ref>
      <ref url="http://www.securityfocus.com/bid/27229" source="BID">27229</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html</ref>
      <ref url="http://securitytracker.com/id?1019218" source="SECTRACK">1019218</ref>
      <ref url="http://secunia.com/advisories/28518" source="SECUNIA" adv="1">28518</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2" source="HP">HPSBMA02133</ref>
      <ref url="http://secunia.com/advisories/28556" source="SECUNIA">28556</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
        <vers num="10.2.0.3"/>
        <vers num="9.2.0.8dv"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0340" published="2008-01-17" name="CVE-2008-0340" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 have unknown impact and remote attack vectors, related to the (1) Advanced Queuing component (DB02) and (2) Oracle Spatial component (DB04).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-017A.html" source="CERT">TA08-017A</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0180" source="VUPEN">ADV-2008-0180</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0150" source="VUPEN">ADV-2008-0150</ref>
      <ref url="http://www.securityfocus.com/bid/27229" source="BID">27229</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html</ref>
      <ref url="http://securitytracker.com/id?1019218" source="SECTRACK">1019218</ref>
      <ref url="http://secunia.com/advisories/28518" source="SECUNIA" adv="1">28518</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2" source="HP">SSRT061201</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2" source="HP">HPSBMA02133</ref>
      <ref url="http://secunia.com/advisories/28556" source="SECUNIA">28556</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="1.0.2.2"/>
        <vers num="10.1.2.0.2"/>
        <vers num="10.1.2.1.0"/>
        <vers num="10.1.2.2.0"/>
        <vers num="10.1.3.0.0"/>
        <vers num="10.1.3.1.0"/>
        <vers num="10.1.3.3.0"/>
        <vers num="9.0.4.3"/>
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="10.1.2"/>
      </prod>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
        <vers num="10.2.0.2"/>
        <vers num="10.2.0.3"/>
        <vers num="11.1.0.6"/>
        <vers num="9.0.1.5" edition=""/>
        <vers num="9.0.1.5" edition=":fips"/>
        <vers num="9.2.0.8"/>
        <vers num="9.2.0.8dv"/>
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10"/>
        <vers num="11.5.10.2"/>
        <vers num="11.5.9"/>
        <vers num="12.0.0"/>
        <vers num="12.0.1"/>
        <vers num="12.0.2"/>
        <vers num="12.0.3"/>
      </prod>
      <prod vendor="oracle" name="peoplesoft_enterprise_peopletools">
        <vers num="8.47"/>
        <vers num="8.48"/>
        <vers num="8.49"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0341" published="2008-01-17" name="CVE-2008-0341" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Advanced Queuing component in Oracle Database 9.0.1.5 FIPS+ and 10.1.0.5 has unknown impact and remote attack vectors, aka DB03.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-017A.html" source="CERT" patch="1">TA08-017A</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0180" source="VUPEN">ADV-2008-0180</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0150" source="VUPEN">ADV-2008-0150</ref>
      <ref url="http://www.securityfocus.com/bid/27229" source="BID">27229</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html</ref>
      <ref url="http://securitytracker.com/id?1019218" source="SECTRACK">1019218</ref>
      <ref url="http://secunia.com/advisories/28518" source="SECUNIA" adv="1">28518</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2" source="HP">SSRT061201</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2" source="HP">HPSBMA02133</ref>
      <ref url="http://secunia.com/advisories/28556" source="SECUNIA">28556</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
        <vers num="9.0.1.5" edition=""/>
        <vers num="9.0.1.5" edition=":fips"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0342" published="2008-01-17" name="CVE-2008-0342" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Upgrade/Downgrade component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and remote attack vectors, aka DB05.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-017A.html" source="CERT" patch="1">TA08-017A</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2" source="HP" patch="1">SSRT061201</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0180" source="VUPEN">ADV-2008-0180</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0150" source="VUPEN">ADV-2008-0150</ref>
      <ref url="http://www.securityfocus.com/bid/27229" source="BID">27229</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html</ref>
      <ref url="http://securitytracker.com/id?1019218" source="SECTRACK">1019218</ref>
      <ref url="http://secunia.com/advisories/28518" source="SECUNIA" adv="1">28518</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2" source="HP">HPSBMA02133</ref>
      <ref url="http://secunia.com/advisories/28556" source="SECUNIA">28556</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
        <vers num="10.2.0.3"/>
        <vers num="9.2.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0343" published="2008-01-17" name="CVE-2008-0343" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Spatial component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 has unknown impact and remote attack vectors, aka DB06.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-017A.html" source="CERT">TA08-017A</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0180" source="VUPEN">ADV-2008-0180</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0150" source="VUPEN">ADV-2008-0150</ref>
      <ref url="http://www.securityfocus.com/bid/27229" source="BID">27229</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html</ref>
      <ref url="http://securitytracker.com/id?1019218" source="SECTRACK">1019218</ref>
      <ref url="http://secunia.com/advisories/28518" source="SECUNIA" adv="1">28518</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2" source="HP">SSRT061201</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2" source="HP">HPSBMA02133</ref>
      <ref url="http://secunia.com/advisories/28556" source="SECUNIA">28556</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="1.0.2.2"/>
        <vers num="10.1.2.0.2"/>
        <vers num="10.1.2.1.0"/>
        <vers num="10.1.2.2.0"/>
        <vers num="10.1.3.0.0"/>
        <vers num="10.1.3.1.0"/>
        <vers num="10.1.3.3.0"/>
        <vers num="9.0.4.3"/>
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="10.1.2"/>
      </prod>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
        <vers num="10.2.0.2"/>
        <vers num="10.2.0.3"/>
        <vers num="11.1.0.6"/>
        <vers num="9.0.1.5" edition=""/>
        <vers num="9.0.1.5" edition=":fips"/>
        <vers num="9.2.0.8"/>
        <vers num="9.2.0.8dv"/>
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10"/>
        <vers num="11.5.10.2"/>
        <vers num="11.5.9"/>
        <vers num="12.0.0"/>
        <vers num="12.0.1"/>
        <vers num="12.0.2"/>
        <vers num="12.0.3"/>
      </prod>
      <prod vendor="oracle" name="peoplesoft_enterprise_peopletools">
        <vers num="8.47"/>
        <vers num="8.48"/>
        <vers num="8.49"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0344" published="2008-01-17" name="CVE-2008-0344" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.3 has unknown impact and remote attack vectors, aka DB07.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-017A.html" source="CERT">TA08-017A</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0180" source="VUPEN">ADV-2008-0180</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0150" source="VUPEN">ADV-2008-0150</ref>
      <ref url="http://www.securityfocus.com/bid/27229" source="BID">27229</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html</ref>
      <ref url="http://securitytracker.com/id?1019218" source="SECTRACK">1019218</ref>
      <ref url="http://secunia.com/advisories/28518" source="SECUNIA" adv="1">28518</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2" source="HP">SSRT061201</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2" source="HP">HPSBMA02133</ref>
      <ref url="http://secunia.com/advisories/28556" source="SECUNIA">28556</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="1.0.2.2"/>
        <vers num="10.1.2.0.2"/>
        <vers num="10.1.2.1.0"/>
        <vers num="10.1.2.2.0"/>
        <vers num="10.1.3.0.0"/>
        <vers num="10.1.3.1.0"/>
        <vers num="10.1.3.3.0"/>
        <vers num="9.0.4.3"/>
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="10.1.2"/>
      </prod>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
        <vers num="10.2.0.2"/>
        <vers num="10.2.0.3"/>
        <vers num="11.1.0.6"/>
        <vers num="9.0.1.5" edition=""/>
        <vers num="9.0.1.5" edition=":fips"/>
        <vers num="9.2.0.8"/>
        <vers num="9.2.0.8dv"/>
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10"/>
        <vers num="11.5.10.2"/>
        <vers num="11.5.9"/>
        <vers num="12.0.0"/>
        <vers num="12.0.1"/>
        <vers num="12.0.2"/>
        <vers num="12.0.3"/>
      </prod>
      <prod vendor="oracle" name="peoplesoft_enterprise_peopletools">
        <vers num="8.47"/>
        <vers num="8.48"/>
        <vers num="8.49"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0345" published="2008-01-17" name="CVE-2008-0345" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Core RDBMS component in Oracle Database 11.1.0.6 has unknown impact and remote attack vectors, aka DB08.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-017A.html" source="CERT">TA08-017A</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0180" source="VUPEN">ADV-2008-0180</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0150" source="VUPEN">ADV-2008-0150</ref>
      <ref url="http://www.securityfocus.com/bid/27229" source="BID">27229</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html</ref>
      <ref url="http://securitytracker.com/id?1019218" source="SECTRACK">1019218</ref>
      <ref url="http://secunia.com/advisories/28518" source="SECUNIA" adv="1">28518</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2" source="HP">SSRT061201</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2" source="HP">HPSBMA02133</ref>
      <ref url="http://secunia.com/advisories/28556" source="SECUNIA">28556</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="1.0.2.2"/>
        <vers num="10.1.2.0.2"/>
        <vers num="10.1.2.1.0"/>
        <vers num="10.1.2.2.0"/>
        <vers num="10.1.3.0.0"/>
        <vers num="10.1.3.1.0"/>
        <vers num="10.1.3.3.0"/>
        <vers num="9.0.4.3"/>
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="10.1.2"/>
      </prod>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
        <vers num="10.2.0.2"/>
        <vers num="10.2.0.3"/>
        <vers num="11.1.0.6"/>
        <vers num="9.0.1.5" edition=""/>
        <vers num="9.0.1.5" edition=":fips"/>
        <vers num="9.2.0.8"/>
        <vers num="9.2.0.8dv"/>
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10"/>
        <vers num="11.5.10.2"/>
        <vers num="11.5.9"/>
        <vers num="12.0.0"/>
        <vers num="12.0.1"/>
        <vers num="12.0.2"/>
        <vers num="12.0.3"/>
      </prod>
      <prod vendor="oracle" name="peoplesoft_enterprise_peopletools">
        <vers num="8.47"/>
        <vers num="8.48"/>
        <vers num="8.49"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0346" published="2008-01-17" name="CVE-2008-0346" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Jinitiator component in Oracle Application Server 1.3.1.27 and E-Business Suite 11.5.10.2 has unknown impact and remote attack vectors, aka AS01.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-017A.html" source="CERT">TA08-017A</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0180" source="VUPEN">ADV-2008-0180</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0150" source="VUPEN">ADV-2008-0150</ref>
      <ref url="http://www.securityfocus.com/bid/27229" source="BID">27229</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html</ref>
      <ref url="http://securitytracker.com/id?1019218" source="SECTRACK">1019218</ref>
      <ref url="http://secunia.com/advisories/28518" source="SECUNIA" adv="1">28518</ref>
      <ref url="http://osvdb.org/40294" source="OSVDB">40294</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2" source="HP">HPSBMA02133</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2" source="HP">HPSBMA02133</ref>
      <ref url="http://secunia.com/advisories/28556" source="SECUNIA">28556</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="1.0.2.2"/>
        <vers num="10.1.2.0.2"/>
        <vers num="10.1.2.1.0"/>
        <vers num="10.1.2.2.0"/>
        <vers num="10.1.3.0.0"/>
        <vers num="10.1.3.1.0"/>
        <vers num="10.1.3.3.0"/>
        <vers num="9.0.4.3"/>
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="10.1.2"/>
      </prod>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
        <vers num="10.2.0.2"/>
        <vers num="10.2.0.3"/>
        <vers num="11.1.0.6"/>
        <vers num="9.0.1.5" edition=""/>
        <vers num="9.0.1.5" edition=":fips"/>
        <vers num="9.2.0.8"/>
        <vers num="9.2.0.8dv"/>
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10"/>
        <vers num="11.5.10.2"/>
        <vers num="11.5.9"/>
        <vers num="12.0.0"/>
        <vers num="12.0.1"/>
        <vers num="12.0.2"/>
        <vers num="12.0.3"/>
      </prod>
      <prod vendor="oracle" name="peoplesoft_enterprise_peopletools">
        <vers num="8.47"/>
        <vers num="8.48"/>
        <vers num="8.49"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0347" published="2008-01-17" name="CVE-2008-0347" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Ultra Search component in Oracle Collaboration Suite 10.1.2; Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; and Application Server 9.0.4.3 and 10.1.2.0.2; has unknown impact and local attack vectors, aka OCS01.  NOTE: Oracle has not disputed a reliable claim that this issue is related to WKSYS schema privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-017A.html" source="CERT">TA08-017A</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0180" source="VUPEN" adv="1">ADV-2008-0180</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0150" source="VUPEN" adv="1">ADV-2008-0150</ref>
      <ref url="http://www.securityfocus.com/bid/27229" source="BID">27229</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487322/100/100/threaded" source="BUGTRAQ">20080130 PeteFinnigan.com Limited advisory for Oracle January 2008 CPU</ref>
      <ref url="http://www.petefinnigan.com/Advisory_CPU_Jan_2008.htm" source="MISC">http://www.petefinnigan.com/Advisory_CPU_Jan_2008.htm</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html</ref>
      <ref url="http://securitytracker.com/id?1019218" source="SECTRACK">1019218</ref>
      <ref url="http://secunia.com/advisories/28556" source="SECUNIA" adv="1">28556</ref>
      <ref url="http://secunia.com/advisories/28518" source="SECUNIA" adv="1">28518</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2" source="HP">SSRT061201</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2" source="HP">HPSBMA02133</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="1.0.2.2"/>
        <vers num="10.1.2.0.2"/>
        <vers num="10.1.2.1.0"/>
        <vers num="10.1.2.2.0"/>
        <vers num="10.1.3.0.0"/>
        <vers num="10.1.3.1.0"/>
        <vers num="10.1.3.3.0"/>
        <vers num="9.0.4.3"/>
      </prod>
      <prod vendor="oracle" name="application_server_9i">
        <vers num="10.1.2.0.2"/>
        <vers num="9.0.4.3"/>
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="10.1.2"/>
      </prod>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
        <vers num="10.2.0.2"/>
        <vers num="10.2.0.3"/>
        <vers num="11.1.0.6"/>
        <vers num="9.0.1.5" edition=""/>
        <vers num="9.0.1.5" edition=":fips"/>
        <vers num="9.2.0.8"/>
        <vers num="9.2.0.8dv"/>
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10"/>
        <vers num="11.5.10.2"/>
        <vers num="11.5.9"/>
        <vers num="12.0.0"/>
        <vers num="12.0.1"/>
        <vers num="12.0.2"/>
        <vers num="12.0.3"/>
      </prod>
      <prod vendor="oracle" name="peoplesoft_enterprise_peopletools">
        <vers num="8.47"/>
        <vers num="8.48"/>
        <vers num="8.49"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0348" published="2008-01-17" name="CVE-2008-0348" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.18, 8.48.15, and 8.49.07 have unknown impact and remote attack vectors, aka (1) PSE01, (2) PSE03, and (3) PSE04.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-017A.html" source="CERT">TA08-017A</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0180" source="VUPEN">ADV-2008-0180</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0150" source="VUPEN">ADV-2008-0150</ref>
      <ref url="http://www.securityfocus.com/bid/27229" source="BID">27229</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html</ref>
      <ref url="http://securitytracker.com/id?1019218" source="SECTRACK">1019218</ref>
      <ref url="http://secunia.com/advisories/28518" source="SECUNIA" adv="1">28518</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2" source="HP">SSRT061201</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2" source="HP">HPSBMA02133</ref>
      <ref url="http://secunia.com/advisories/28556" source="SECUNIA">28556</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="1.0.2.2"/>
        <vers num="10.1.2.0.2"/>
        <vers num="10.1.2.1.0"/>
        <vers num="10.1.2.2.0"/>
        <vers num="10.1.3.0.0"/>
        <vers num="10.1.3.1.0"/>
        <vers num="10.1.3.3.0"/>
        <vers num="9.0.4.3"/>
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="10.1.2"/>
      </prod>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
        <vers num="10.2.0.2"/>
        <vers num="10.2.0.3"/>
        <vers num="11.1.0.6"/>
        <vers num="9.0.1.5" edition=""/>
        <vers num="9.0.1.5" edition=":fips"/>
        <vers num="9.2.0.8"/>
        <vers num="9.2.0.8dv"/>
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10"/>
        <vers num="11.5.10.2"/>
        <vers num="11.5.9"/>
        <vers num="12.0.0"/>
        <vers num="12.0.1"/>
        <vers num="12.0.2"/>
        <vers num="12.0.3"/>
      </prod>
      <prod vendor="oracle" name="peoplesoft_enterprise_peopletools">
        <vers num="8.47"/>
        <vers num="8.48"/>
        <vers num="8.49"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0349" published="2008-01-17" name="CVE-2008-0349" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.15 and 8.49.07 has unknown impact and remote attack vectors, aka PSE02.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-017A.html" source="CERT">TA08-017A</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0180" source="VUPEN">ADV-2008-0180</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0150" source="VUPEN">ADV-2008-0150</ref>
      <ref url="http://www.securityfocus.com/bid/27229" source="BID">27229</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2008-086860.html</ref>
      <ref url="http://securitytracker.com/id?1019218" source="SECTRACK">1019218</ref>
      <ref url="http://secunia.com/advisories/28518" source="SECUNIA" adv="1">28518</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2" source="HP">SSRT061201</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2" source="HP">HPSBMA02133</ref>
      <ref url="http://secunia.com/advisories/28556" source="SECUNIA">28556</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="1.0.2.2"/>
        <vers num="10.1.2.0.2"/>
        <vers num="10.1.2.1.0"/>
        <vers num="10.1.2.2.0"/>
        <vers num="10.1.3.0.0"/>
        <vers num="10.1.3.1.0"/>
        <vers num="10.1.3.3.0"/>
        <vers num="9.0.4.3"/>
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="10.1.2"/>
      </prod>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
        <vers num="10.2.0.2"/>
        <vers num="10.2.0.3"/>
        <vers num="11.1.0.6"/>
        <vers num="9.0.1.5" edition=""/>
        <vers num="9.0.1.5" edition=":fips"/>
        <vers num="9.2.0.8"/>
        <vers num="9.2.0.8dv"/>
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10"/>
        <vers num="11.5.10.2"/>
        <vers num="11.5.9"/>
        <vers num="12.0.0"/>
        <vers num="12.0.1"/>
        <vers num="12.0.2"/>
        <vers num="12.0.3"/>
      </prod>
      <prod vendor="oracle" name="peoplesoft_enterprise_peopletools">
        <vers num="8.47"/>
        <vers num="8.48"/>
        <vers num="8.49"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0350" published="2008-01-17" name="CVE-2008-0350" modified="2009-09-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">admin/index.php in Evilsentinel 1.0.9 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to gain administrative privileges and make arbitrary configuration changes.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/28427" source="SECUNIA" patch="1">28427</ref>
      <ref url="http://www.securityfocus.com/bid/27227" source="BID">27227</ref>
      <ref url="http://www.milw0rm.com/exploits/4884" source="MILW0RM">4884</ref>
      <ref url="http://evilsentinel.altervista.org/forum/index.php?topic=49.0" source="CONFIRM">http://evilsentinel.altervista.org/forum/index.php?topic=49.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="evilsentinel" name="evilsentinel">
        <vers prev="1" num="1.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0351" published="2008-01-17" name="CVE-2008-0351" modified="2009-09-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">admin/config.php in Evilsentinel 1.0.9 and earlier allows remote attackers to bypass the CAPTCHA test by omitting the es_security_captcha parameter and not invoking captcha.php.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27227" source="BID">27227</ref>
      <ref url="http://www.milw0rm.com/exploits/4884" source="MILW0RM">4884</ref>
    </refs>
    <vuln_soft>
      <prod vendor="evilsentinel" name="evilsentinel">
        <vers prev="1" num="1.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0352" published="2008-01-17" name="CVE-2008-0352" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The Linux kernel 2.6.20 through 2.6.21.1 allows remote attackers to cause a denial of service (panic) via a certain IPv6 packet, possibly involving the Jumbo Payload hop-by-hop option (jumbogram).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39643" source="XF">linux-kernel-ipv6-jumbogram-dos(39643)</ref>
      <ref url="http://www.milw0rm.com/exploits/4893" source="MILW0RM">4893</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.21.2" source="MISC">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.21.2</ref>
      <ref url="http://bugzilla.kernel.org/show_bug.cgi?id=8450" source="CONFIRM">http://bugzilla.kernel.org/show_bug.cgi?id=8450</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.2" edition="rc1"/>
        <vers num="2.6.2" edition="rc2"/>
        <vers num="2.6.2" edition="rc3"/>
        <vers num="2.6.20" edition="rc2"/>
        <vers num="2.6.20.1"/>
        <vers num="2.6.20.10"/>
        <vers num="2.6.20.11"/>
        <vers num="2.6.20.12"/>
        <vers num="2.6.20.13"/>
        <vers num="2.6.20.14"/>
        <vers num="2.6.20.15"/>
        <vers num="2.6.20.2"/>
        <vers num="2.6.20.3"/>
        <vers num="2.6.20.4"/>
        <vers num="2.6.20.5"/>
        <vers num="2.6.20.6"/>
        <vers num="2.6.20.7"/>
        <vers num="2.6.20.8"/>
        <vers num="2.6.20.9"/>
        <vers num="2.6.21" edition="git1"/>
        <vers num="2.6.21" edition="git2"/>
        <vers num="2.6.21" edition="git3"/>
        <vers num="2.6.21" edition="git4"/>
        <vers num="2.6.21" edition="git5"/>
        <vers num="2.6.21" edition="git6"/>
        <vers num="2.6.21" edition="git7"/>
        <vers num="2.6.21.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0353" published="2008-01-18" name="CVE-2008-0353" modified="2008-10-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in visualizza_tabelle.php in php-residence 0.7.2 and 1.0 allows remote attackers to execute arbitrary SQL commands via the cognome_cerca parameter.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39739" source="XF">phpresidence-visualizza-sql-injection(39739)</ref>
      <ref url="http://www.securityfocus.com/bid/27320" source="BID">27320</ref>
      <ref url="http://www.milw0rm.com/exploits/4925" source="MILW0RM">4925</ref>
      <ref url="http://secunia.com/advisories/28516" source="SECUNIA" adv="1">28516</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php-residence" name="php-residence">
        <vers num="0.7.2"/>
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0354" published="2008-01-18" name="CVE-2008-0354" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the chat client in IBM Lotus Sametime 7.5 and 7.5.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted message, which triggers code execution after a mouseover event initiated by the victim.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0168" source="VUPEN">ADV-2008-0168</ref>
      <ref url="http://www.securitytracker.com/id?1019224" source="SECTRACK">1019224</ref>
      <ref url="http://www.securityfocus.com/bid/27316" source="BID">27316</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21292938" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg21292938</ref>
      <ref url="http://secunia.com/advisories/27942" source="SECUNIA" adv="1">27942</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39726" source="XF">sametime-client-mouseover-xss(39726)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_sametime">
        <vers num="7.5"/>
        <vers num="7.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0355" published="2008-01-18" name="CVE-2008-0355" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in the forum module in PHPEcho CMS, probably 2.0-rc3 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter in a section action, a different vector than CVE-2007-2866.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27326" source="BID">27326</ref>
      <ref url="http://www.milw0rm.com/exploits/4929" source="MILW0RM">4929</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39741" source="XF">phpechocms-index-sql-injection(39741)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpecho_cms" name="phpecho_cms">
        <vers prev="1" num="2.0-rc3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0356" published="2008-01-18" name="CVE-2008-0356" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the Independent Management Architecture (IMA) service in Citrix Presentation Server (MetaFrame Presentation Server) 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 allows remote attackers to execute arbitrary code via an invalid size value in a packet to TCP port 2512 or 2513.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/412228" source="CERT-VN">VU#412228</ref>
      <ref url="http://support.citrix.com/article/CTX114487" source="CONFIRM" patch="1">http://support.citrix.com/article/CTX114487</ref>
      <ref url="http://zerodayinitiative.com/advisories/ZDI-08-002.html" source="MISC">http://zerodayinitiative.com/advisories/ZDI-08-002.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0172" source="VUPEN">ADV-2008-0172</ref>
      <ref url="http://secunia.com/advisories/28508" source="SECUNIA" adv="1">28508</ref>
      <ref url="http://www.securitytracker.com/id?1019231" source="SECTRACK">1019231</ref>
      <ref url="http://www.securityfocus.com/bid/27329" source="BID">27329</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486585/100/0/threaded" source="BUGTRAQ">20080117 ZDI-08-002: Citrix Presentation Server IMA Service Heap Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citrix" name="access_essentials">
        <vers prev="1" num="2.0"/>
      </prod>
      <prod vendor="citrix" name="desktop_server">
        <vers num="1.0"/>
      </prod>
      <prod vendor="citrix" name="metaframe_presentation_server">
        <vers prev="1" num="4.5"/>
      </prod>
      <prod vendor="citrix" name="presentation_server">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0357" published="2008-01-18" name="CVE-2008-0357" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in pages/upload.php in Galaxyscripts Mini File Host 1.2.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27327" source="BID">27327</ref>
      <ref url="http://www.milw0rm.com/exploits/4930" source="MILW0RM">4930</ref>
      <ref url="http://secunia.com/advisories/28504" source="SECUNIA" adv="1">28504</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39799" source="XF">minifilehost-uploadphp-file-include(39799)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="galaxyscripts" name="mini_file_host">
        <vers prev="1" num="1.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0358" published="2008-01-18" name="CVE-2008-0358" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Pixelpost 1.7 allows remote attackers to execute arbitrary SQL commands via the parent_id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.pixelpost.org/forum/showthread.php?t=7716" source="CONFIRM" patch="1">http://www.pixelpost.org/forum/showthread.php?t=7716</ref>
      <ref url="http://www.securityfocus.com/bid/27242" source="BID">27242</ref>
      <ref url="http://www.milw0rm.com/exploits/4924" source="MILW0RM">4924</ref>
      <ref url="http://secunia.com/advisories/28499" source="SECUNIA" adv="1">28499</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39721" source="XF">pixelpost-indexphp-sql-injection(39721)</ref>
      <ref url="http://www.securitytracker.com/id?1019238" source="SECTRACK">1019238</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pixelpost" name="pixelpost">
        <vers num="1.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0359" published="2008-01-18" name="CVE-2008-0359" modified="2009-09-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin.php or (2) index.php in photo/.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27317" source="BID" patch="1">27317</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39710" source="XF">blogcms-index-xss(39710)</ref>
      <ref url="http://secunia.com/advisories/28523" source="SECUNIA" adv="1">28523</ref>
      <ref url="http://milw0rm.com/exploits/4919" source="MILW0RM">4919</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120049816924383&amp;w=2" source="BUGTRAQ">20080116 [DSECRG-08-003] blogcms 4.2.1b Multiple Security Vulnerabilities</ref>
      <ref url="http://blogcms.com/wiki/changelog" source="CONFIRM">http://blogcms.com/wiki/changelog</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blog_cms" name="blog_cms">
        <vers num="4.2.1_c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0360" published="2008-01-18" name="CVE-2008-0360" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to execute arbitrary SQL commands via (1) the blogid parameter to index.php, (2) the user parameter to action.php, or (3) the field parameter to admin/plugins/table/index.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27317" source="BID" patch="1">27317</ref>
      <ref url="http://secunia.com/advisories/28523" source="SECUNIA" adv="1">28523</ref>
      <ref url="http://milw0rm.com/exploits/4919" source="MILW0RM">4919</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120049816924383&amp;w=2" source="BUGTRAQ">20080116 [DSECRG-08-003] blogcms 4.2.1b Multiple Security Vulnerabilities</ref>
      <ref url="http://blogcms.com/wiki/changelog" source="CONFIRM">http://blogcms.com/wiki/changelog</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blog_cms" name="blog_cms">
        <vers num="4.2.1_c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0361" published="2008-01-18" name="CVE-2008-0361" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in agregar_info.php in GradMan 0.1.3 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tabla parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27324" source="BID">27324</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486444/100/0/threaded" source="BUGTRAQ">20080116 Gradman &lt;= 0.1.3 (agregar_info.php?tabla=) Local File Inclusion Exploit</ref>
      <ref url="http://www.milw0rm.com/exploits/4926" source="MILW0RM">4926</ref>
      <ref url="http://secunia.com/advisories/28520" source="SECUNIA" adv="1">28520</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39732" source="XF">gradman-agregarinfo-file-include(39732)</ref>
      <ref url="http://securityreason.com/securityalert/3552" source="SREASON">3552</ref>
    </refs>
    <vuln_soft>
      <prod vendor="instituto_politicnico_nacional" name="gradman">
        <vers prev="1" num="0.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0362" published="2008-01-18" name="CVE-2008-0362" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in gallery.php in Clever Copy 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the album parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486492/100/0/threaded" source="BUGTRAQ">20080117 Clever Copy &lt;=3.0 Multiple Remote Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39747" source="XF">clevercopy-gallery-xss(39747)</ref>
      <ref url="http://www.securityfocus.com/bid/27335" source="BID">27335</ref>
      <ref url="http://securityreason.com/securityalert/3553" source="SREASON">3553</ref>
      <ref url="http://secunia.com/advisories/28560" source="SECUNIA">28560</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clever_copy" name="clever_copy">
        <vers prev="1" num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0363" published="2008-01-18" name="CVE-2008-0363" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Clever Copy 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to postcomment.php and the (2) album parameter to gallery.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486492/100/0/threaded" source="BUGTRAQ">20080117 Clever Copy &lt;=3.0 Multiple Remote Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39746" source="XF">clevercopy-postcomment-sql-injection(39746)</ref>
      <ref url="http://www.securityfocus.com/bid/27335" source="BID">27335</ref>
      <ref url="http://securityreason.com/securityalert/3553" source="SREASON">3553</ref>
      <ref url="http://secunia.com/advisories/28560" source="SECUNIA">28560</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clever_copy" name="clever_copy">
        <vers prev="1" num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0364" published="2008-01-18" name="CVE-2008-0364" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in (1) BitTorrent 6.0 and earlier; and (2) uTorrent 1.7.5 and earlier, and 1.8-alpha-7834 and earlier in the 1.8.x series; on Windows allows remote attackers to cause a denial of service (application crash) via a long Unicode string representing a client version identifier.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27321" source="BID" patch="1">27321</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39720" source="XF">utorrent-peers-bo(39720)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39719" source="XF">bittorrent-peers-bo(39719)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486426/100/0/threaded" source="BUGTRAQ">20080116 Peers static overflow in BitTorrent 6.0 and uTorrent 1.7.5</ref>
      <ref url="http://download.utorrent.com/1.7.6/utorrent-1.7.6.txt" source="CONFIRM">http://download.utorrent.com/1.7.6/utorrent-1.7.6.txt</ref>
      <ref url="http://aluigi.org/poc/ruttorrent.zip" source="MISC">http://aluigi.org/poc/ruttorrent.zip</ref>
      <ref url="http://aluigi.altervista.org/adv/ruttorrent-adv.txt" source="MISC">http://aluigi.altervista.org/adv/ruttorrent-adv.txt</ref>
      <ref url="http://securityreason.com/securityalert/3554" source="SREASON">3554</ref>
      <ref url="http://secunia.com/advisories/28537" source="SECUNIA">28537</ref>
      <ref url="http://secunia.com/advisories/28533" source="SECUNIA">28533</ref>
      <ref url="http://forum.utorrent.com/viewtopic.php?id=29330" source="CONFIRM">http://forum.utorrent.com/viewtopic.php?id=29330</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bittorrent" name="bittorrent">
        <vers prev="1" num="6.0"/>
      </prod>
      <prod vendor="utorrent" name="utorrent">
        <vers prev="1" num="1.7.5"/>
        <vers num="1.8-alpha-7834"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0365" published="2008-01-18" name="CVE-2008-0365" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in CORE FORCE before 0.95.172 allow local users to cause a denial of service (system crash) and possibly execute arbitrary code in the kernel context via crafted arguments to (1) IOCTL functions in the Firewall module or (2) SSDT hook handler functions in the Registry module.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0242" source="VUPEN">ADV-2008-0242</ref>
      <ref url="http://www.securityfocus.com/bid/27341" source="BID">27341</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486513/100/0/threaded" source="BUGTRAQ">20080117 CORE-2007-1119: CORE FORCE Kernel Buffer Overflow</ref>
      <ref url="http://www.coresecurity.com/?action=item&amp;id=2025" source="CONFIRM">http://www.coresecurity.com/?action=item&amp;id=2025</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39758" source="XF">coreforce-firewall-registry-bo(39758)</ref>
      <ref url="http://www.securitytracker.com/id?1019245" source="SECTRACK">1019245</ref>
      <ref url="http://securityreason.com/securityalert/3555" source="SREASON">3555</ref>
      <ref url="http://force.coresecurity.com/index.php?module=articles&amp;func=display&amp;aid=32" source="CONFIRM">http://force.coresecurity.com/index.php?module=articles&amp;func=display&amp;aid=32</ref>
    </refs>
    <vuln_soft>
      <prod vendor="core_security_technologies" name="core_force">
        <vers prev="1" num="0.95.167"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0366" published="2008-01-18" name="CVE-2008-0366" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">CORE FORCE before 0.95.172 does not properly validate arguments to SSDT hook handler functions in the Registry module, which allows local users to cause a denial of service (system crash) and possibly execute arbitrary code in the kernel context via crafted arguments.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27341" source="BID" patch="1">27341</ref>
      <ref url="http://www.coresecurity.com/?action=item&amp;id=2025" source="CONFIRM" patch="1">http://www.coresecurity.com/?action=item&amp;id=2025</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0242" source="VUPEN">ADV-2008-0242</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486513/100/0/threaded" source="BUGTRAQ">20080117 CORE-2007-1119: CORE FORCE Kernel Buffer Overflow</ref>
      <ref url="http://www.securitytracker.com/id?1019245" source="SECTRACK">1019245</ref>
      <ref url="http://securityreason.com/securityalert/3555" source="SREASON">3555</ref>
      <ref url="http://force.coresecurity.com/index.php?module=articles&amp;func=display&amp;aid=32" source="CONFIRM">http://force.coresecurity.com/index.php?module=articles&amp;func=display&amp;aid=32</ref>
    </refs>
    <vuln_soft>
      <prod vendor="core_security_technologies" name="core_force">
        <vers prev="1" num="0.95.167"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0367" published="2008-01-18" name="CVE-2008-0367" modified="2008-10-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mozilla Firefox 2.0.0.11, 3.0b2, and possibly earlier versions, when prompting for HTTP Basic Authentication, displays the site requesting the authentication after the Realm text, which might make it easier for remote HTTP servers to conduct phishing and spoofing attacks.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=244273" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=244273</ref>
      <ref url="http://www.securityfocus.com/bid/27111" source="BID">27111</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485738/100/200/threaded" source="BUGTRAQ">20080103 Re: [Full-disclosure] Yet another Dialog Spoofing Vulnerability - Firefox Basic Authentication</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485732/100/200/threaded" source="BUGTRAQ">20080103 Yet another Dialog Spoofing Vulnerability - Firefox Basic Authentication</ref>
      <ref url="http://blog.mozilla.com/security/2008/01/04/basicauth-dialog-realm-value-spoofing/" source="CONFIRM">http://blog.mozilla.com/security/2008/01/04/basicauth-dialog-realm-value-spoofing/</ref>
      <ref url="http://aviv.raffon.net/2008/01/05/FirefoxDialogSpoofingFAQ.aspx" source="MISC">http://aviv.raffon.net/2008/01/05/FirefoxDialogSpoofingFAQ.aspx</ref>
      <ref url="http://aviv.raffon.net/2008/01/02/YetAnotherDialogSpoofingFirefoxBasicAuthentication.aspx" source="MISC">http://aviv.raffon.net/2008/01/02/YetAnotherDialogSpoofingFirefoxBasicAuthentication.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers prev="1" num="2.0.0.11"/>
        <vers prev="1" num="3.0" edition="beta2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0368" published="2008-01-18" name="CVE-2008-0368" modified="2011-05-11" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">onedcu in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allows local users to create arbitrary files via the Trace file argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39751" source="XF">ibm-ids-onedcu-sqlidebug-unspecified(39751)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0169" source="VUPEN" adv="1">ADV-2008-0169</ref>
      <ref url="http://www.securitytracker.com/id?1019237" source="SECTRACK">1019237</ref>
      <ref url="http://www.securityfocus.com/bid/27328" source="BID">27328</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg27011556" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg27011556</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1IC54307" source="AIXAPAR">IC54307</ref>
      <ref url="http://secunia.com/advisories/28534" source="SECUNIA" adv="1">28534</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=651" source="IDEFENSE">20080131 IBM Informix Dynamic Server onedcu File Creation Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="informix_dynamic_server">
        <vers num="10.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0369" published="2008-01-18" name="CVE-2008-0369" modified="2011-05-11" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Multiple unspecified programs in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allow local users to create arbitrary files by specifying the target file in the SQLIDEBUG environment variable, whose ownership is changed to the user invoking the programs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/40009" source="XF">ibm-ids-sqlidebug-unspecified(40009)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39751" source="XF">ibm-ids-onedcu-sqlidebug-unspecified(39751)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0169" source="VUPEN" adv="1">ADV-2008-0169</ref>
      <ref url="http://www.securitytracker.com/id?1019237" source="SECTRACK">1019237</ref>
      <ref url="http://www.securityfocus.com/bid/27328" source="BID">27328</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg27011556" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg27011556</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1IC54309" source="AIXAPAR">IC54309</ref>
      <ref url="http://secunia.com/advisories/28534" source="SECUNIA" adv="1">28534</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=650" source="IDEFENSE">20080131 IBM Informix Dynamic Server SQLIDEBUG File Creation Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="informix_dynamic_server">
        <vers num="10.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0370" published="2008-01-22" name="CVE-2008-0370" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in dohtaccess.html in cPanel before 11.17 build 19417 allows remote attackers to inject arbitrary web script or HTML via the rurl parameter.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27308" source="BID">27308</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486404/100/0/threaded" source="BUGTRAQ">20080116 cPanel Hosting Manager (dohtaccess.html)</ref>
      <ref url="http://secunia.com/advisories/28561" source="SECUNIA">28561</ref>
      <ref url="http://aria-security.net/forum/showthread.php?p=1238" source="MISC">http://aria-security.net/forum/showthread.php?p=1238</ref>
      <ref url="http://securityreason.com/securityalert/3561" source="SREASON">3561</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cpanel" name="cpanel">
        <vers num="11.16"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0371" published="2008-01-22" name="CVE-2008-0371" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in aliTalk 1.9.1.1, when magic_quotes_gpc is disabled, allow remote authenticated users to execute arbitrary SQL commands via (1) the mohit parameter to (a) inc/receivertwo.php; and allow remote attackers to execute arbitrary SQL commands via (2) the id parameter to (b) inc/usercp.php, related to functionz/usercp.php; or (3) the username parameter to (c) admin/index.php, related to functionz/first_process.php, or (d) index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39745" source="XF">alitalk-index-sql-injection(39745)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39736" source="XF">alitalk-usercp-sql-injection(39736)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39735" source="XF">alitalk-adminindex-sql-injection(39735)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39733" source="XF">alitalk-receivertwo-sql-injection(39733)</ref>
      <ref url="http://www.securityfocus.com/bid/27315" source="BID">27315</ref>
      <ref url="http://www.milw0rm.com/exploits/4922" source="MILW0RM">4922</ref>
      <ref url="http://secunia.com/advisories/28515" source="SECUNIA" adv="1">28515</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alilg" name="alitalk">
        <vers num="1.9.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0372" published="2008-01-22" name="CVE-2008-0372" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">8e6 R3000 Internet Filter 2.0.05.33, and other versions before 2.0.11, allows remote attackers to bypass intended restrictions via a fragmented HTTP request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39723" source="XF">r3000-urlfilter-security-bypass(39723)</ref>
      <ref url="http://www.securityfocus.com/bid/27309" source="BID">27309</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486770/100/0/threaded" source="BUGTRAQ">20080121 Re: 8e6 Technologies R3000 Internet Filter Bypass by Request Split</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486398/100/0/threaded" source="BUGTRAQ">20080116 8e6 Technologies R3000 Internet Filter Bypass by Request Split</ref>
      <ref url="http://secunia.com/advisories/28524" source="SECUNIA" adv="1">28524</ref>
      <ref url="http://securityreason.com/securityalert/3557" source="SREASON">3557</ref>
    </refs>
    <vuln_soft>
      <prod vendor="8e6" name="r3000_internet_filter">
        <vers prev="1" num="2.0.05.33"/>
        <vers prev="1" num="2.0.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0373" published="2008-01-22" name="CVE-2008-0373" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in PHP F1 Max's File Uploader allows remote attackers to upload and execute arbitrary PHP files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39740" source="XF">max-index-file-upload(39740)</ref>
      <ref url="http://www.securityfocus.com/bid/27285" source="BID">27285</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486335/100/0/threaded" source="BUGTRAQ">20080115 Max's File Uploader File Upload Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/3572" source="SREASON">3572</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="f1_maxs_file_uploader">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0374" published="2008-01-22" name="CVE-2008-0374" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">OKI C5510MFP Printer CU H2.15, PU 01.03.01, System F/W 1.01, and Web Page 1.00 sends the configuration of the printer in cleartext, which allows remote attackers to obtain the administrative password by connecting to TCP port 5548 or 7777.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27339" source="BID">27339</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486511/100/0/threaded" source="BUGTRAQ">20080117 [CSNC] OKI C5510MFP Printer Password Disclosure</ref>
      <ref url="http://www.csnc.ch/en/modules/news/news_0004.html_1394092626.html" source="MISC">http://www.csnc.ch/en/modules/news/news_0004.html_1394092626.html</ref>
      <ref url="http://secunia.com/advisories/28553" source="SECUNIA" adv="1">28553</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39775" source="XF">c5510mfp-configuration-info-disclosure(39775)</ref>
      <ref url="http://securityreason.com/securityalert/3569" source="SREASON">3569</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oki_printing_solutions" name="c5510_mfp_printer">
        <vers num="cu_h2.15"/>
        <vers num="pu_01.03.01"/>
        <vers num="system_fw_1.01"/>
        <vers num="web_page_1.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0375" published="2008-01-22" name="CVE-2008-0375" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in OKI C5510MFP Printer CU H2.15, PU 01.03.01, System F/W 1.01, and Web Page 1.00 allows remote attackers to set the password and obtain administrative access via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27339" source="BID">27339</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486511/100/0/threaded" source="BUGTRAQ">20080117 [CSNC] OKI C5510MFP Printer Password Disclosure</ref>
      <ref url="http://www.csnc.ch/en/modules/news/news_0004.html_1394092626.html" source="MISC">http://www.csnc.ch/en/modules/news/news_0004.html_1394092626.html</ref>
      <ref url="http://secunia.com/advisories/28553" source="SECUNIA" adv="1">28553</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39776" source="XF">c5510mfp-password-security-bypass(39776)</ref>
      <ref url="http://securityreason.com/securityalert/3569" source="SREASON">3569</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oki_printing_solutions" name="c5510_mfp_printer">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0376" published="2008-01-22" name="CVE-2008-0376" modified="2008-10-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the cfile parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27345" source="BID">27345</ref>
      <ref url="http://www.milw0rm.com/exploits/4937" source="MILW0RM">4937</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39765" source="XF">smallaxeweblog-linkbar-file-include(39765)</ref>
      <ref url="http://secunia.com/advisories/28568" source="SECUNIA">28568</ref>
    </refs>
    <vuln_soft>
      <prod vendor="softpedia" name="small_axe_weblog">
        <vers num="0.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0377" published="2008-01-22" name="CVE-2008-0377" modified="2009-09-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">MicroNews allows remote attackers to bypass authentication and gain administrative privileges via a direct request to admin.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39702" source="XF">micronews-admin-authentication-bypass(39702)</ref>
      <ref url="http://www.securityfocus.com/bid/27288" source="BID">27288</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486349/100/0/threaded" source="BUGTRAQ">20080115 MicroNews Admin Direct Access vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/3556" source="SREASON">3556</ref>
    </refs>
    <vuln_soft>
      <prod vendor="news" name="micronews">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0378" published="2008-01-22" name="CVE-2008-0378" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in SocksCap 2.40-051231 and earlier, when "Resolve all names remotely" is enabled, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long hostname.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27357" source="BID">27357</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486632/100/0/threaded" source="BUGTRAQ">20080118 SocksCap Stack Overflow (&lt;= 2.40-051231)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39781" source="XF">sockscap-hostname-bo(39781)</ref>
      <ref url="http://securityreason.com/securityalert/3560" source="SREASON">3560</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nec" name="sockscap">
        <vers prev="1" num="2.40_051231"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0379" published="2008-01-22" name="CVE-2008-0379" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SelectedSession method, which triggers a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39743" source="XF">crystalreports-enterprisetree-bo(39743)</ref>
      <ref url="http://www.securitytracker.com/id?1019239" source="SECTRACK">1019239</ref>
      <ref url="http://www.securityfocus.com/bid/27333" source="BID">27333</ref>
      <ref url="http://www.milw0rm.com/exploits/4931" source="MILW0RM">4931</ref>
    </refs>
    <vuln_soft>
      <prod vendor="businessobjects" name="crystal_reports_xi">
        <vers num="r2"/>
      </prod>
      <prod vendor="microsoft" name="activex">
        <vers num="enterprise_tree_control"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0380" published="2008-01-22" name="CVE-2008-0380" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the Digital Data Communications RtspVaPgCtrl ActiveX control (RtspVapgDecoder.dll 1.1.0.29) allows remote attackers to execute arbitrary code via a long MP4Prefix property.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0182" source="VUPEN">ADV-2008-0182</ref>
      <ref url="http://www.securityfocus.com/bid/27337" source="BID">27337</ref>
      <ref url="http://www.milw0rm.com/exploits/4932" source="MILW0RM">4932</ref>
      <ref url="http://secunia.com/advisories/28492" source="SECUNIA">28492</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digital_data_communications" name="rtspvapgdecoder.dll">
        <vers num="1.1.0.29"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0381" published="2008-01-22" name="CVE-2008-0381" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Mahara before 0.9.1 has unknown impact and remote attack vectors, probably related to cross-site scripting (XSS) in uploaded files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://eduforge.org/frs/shownotes.php?release_id=342" source="CONFIRM" patch="1">https://eduforge.org/frs/shownotes.php?release_id=342</ref>
      <ref url="http://www.securityfocus.com/bid/27348" source="BID">27348</ref>
      <ref url="http://secunia.com/advisories/28484" source="SECUNIA" adv="1">28484</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mahara" name="mahara">
        <vers prev="1" num="0.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0382" published="2008-01-22" name="CVE-2008-0382" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via the sortby parameter to (1) forumdisplay.php or (2) a results action in search.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27322" source="BID">27322</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486434/100/0/threaded" source="BUGTRAQ">20080116 [waraxe-2008-SA#061] - Remote Code Execution in MyBB 1.2.10</ref>
      <ref url="http://www.milw0rm.com/exploits/4928" source="MILW0RM">4928</ref>
      <ref url="http://www.milw0rm.com/exploits/4927" source="MILW0RM">4927</ref>
      <ref url="http://secunia.com/advisories/28509" source="SECUNIA" adv="1">28509</ref>
      <ref url="http://securityreason.com/securityalert/3559" source="SREASON">3559</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0_pr2"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.10"/>
        <vers num="1.2"/>
        <vers num="1.2.10"/>
        <vers num="1.2.3"/>
        <vers num="1.2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0383" published="2008-01-22" name="CVE-2008-0383" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in MyBB 1.2.10 and earlier allow remote moderators and administrators to execute arbitrary SQL commands via (1) the mergepost parameter in a do_mergeposts action, (2) rid parameter in an allreports action, or (3) threads parameter in a do_multimovethreads action to (a) moderation.php; or (4) gid parameter to (b) admin/usergroups.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27323" source="BID" patch="1">27323</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39729" source="XF">mybb-usergroups-sql-injection(39729)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39728" source="XF">mybb-moderationphp-sql-injection(39728)</ref>
      <ref url="http://www.waraxe.us/advisory-62.html" source="MISC">http://www.waraxe.us/advisory-62.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486433/100/0/threaded" source="BUGTRAQ">20080116 [waraxe-2008-SA#062] - Multiple Sql Injections in MyBB 1.2.10</ref>
      <ref url="http://secunia.com/advisories/28509" source="SECUNIA" adv="1">28509</ref>
      <ref url="http://community.mybboard.net/showthread.php?tid=27227" source="CONFIRM">http://community.mybboard.net/showthread.php?tid=27227</ref>
      <ref url="http://securityreason.com/securityalert/3558" source="SREASON">3558</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybb" name="mybb">
        <vers prev="1" num="1.2.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0384" published="2008-01-22" name="CVE-2008-0384" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">OpenBSD 4.2 allows local users to cause a denial of service (kernel panic) by calling the SIOCGIFRTLABEL IOCTL on an interface that does not have a route label, which triggers a NULL pointer dereference when the return value from the rtlabel_id2name function is not checked.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1019188" source="SECTRACK">1019188</ref>
      <ref url="http://www.securityfocus.com/bid/27252" source="BID">27252</ref>
      <ref url="http://www.openbsd.org/errata42.html#005_ifrtlabel" source="OPENBSD">[4.2] 20080111 005: RELIABILITY FIX: January 11, 2008</ref>
      <ref url="http://www.milw0rm.com/exploits/4935" source="MILW0RM">4935</ref>
      <ref url="http://secunia.com/advisories/28473" source="SECUNIA" adv="1">28473</ref>
      <ref url="http://marc.info/?l=openbsd-security-announce&amp;m=120007327504064" source="MLIST">[openbsd-security-announce] 20080111 errata 005 for OpenBSD 4.2: local users can provoke a kernel panic</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0385" published="2008-02-29" name="CVE-2008-0385" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in server/widgetallocator.php in Urulu 2.1 allows remote attackers to execute arbitrary SQL commands via the connectionId parameter to index.php with (1) statprt/js/request or (2) dyn/js/request in the PATH_INFO.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/28032" source="BID" patch="1">28032</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488909/100/0/threaded" source="BUGTRAQ">20080228 Urulu 2.1 Blind SQL Injection Vulnerability (CVE-2008-0385)</ref>
      <ref url="http://www.csnc.ch/misc/files/advisories/CVE-2008-0385.txt" source="MISC">http://www.csnc.ch/misc/files/advisories/CVE-2008-0385.txt</ref>
      <ref url="http://securityreason.com/securityalert/3707" source="SREASON">3707</ref>
      <ref url="http://secunia.com/advisories/29162" source="SECUNIA">29162</ref>
    </refs>
    <vuln_soft>
      <prod vendor="urulu" name="urulu">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0386" published="2008-02-04" name="CVE-2008-0386" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Xdg-utils 1.0.2 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a URL argument to (1) xdg-open or (2) xdg-email.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=429513" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=429513</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0342" source="VUPEN">ADV-2008-0342</ref>
      <ref url="http://www.securitytracker.com/id?1019284" source="SECTRACK">1019284</ref>
      <ref url="http://www.securityfocus.com/bid/27528" source="BID">27528</ref>
      <ref url="http://webcvs.freedesktop.org/portland/portland/xdg-utils/scripts/xdg-open?view=log" source="CONFIRM">http://webcvs.freedesktop.org/portland/portland/xdg-utils/scripts/xdg-open?view=log</ref>
      <ref url="http://webcvs.freedesktop.org/portland/portland/xdg-utils/scripts/xdg-open?r1=1.32&amp;r2=1.33" source="CONFIRM">http://webcvs.freedesktop.org/portland/portland/xdg-utils/scripts/xdg-open?r1=1.32&amp;r2=1.33</ref>
      <ref url="http://webcvs.freedesktop.org/portland/portland/xdg-utils/scripts/xdg-open.in?r1=1.17&amp;r2=1.18" source="CONFIRM">http://webcvs.freedesktop.org/portland/portland/xdg-utils/scripts/xdg-open.in?r1=1.17&amp;r2=1.18</ref>
      <ref url="http://webcvs.freedesktop.org/portland/portland/xdg-utils/scripts/xdg-email?r1=1.36&amp;r2=1.37" source="CONFIRM">http://webcvs.freedesktop.org/portland/portland/xdg-utils/scripts/xdg-email?r1=1.36&amp;r2=1.37</ref>
      <ref url="http://webcvs.freedesktop.org/portland/portland/xdg-utils/scripts/xdg-email.in?view=log" source="CONFIRM">http://webcvs.freedesktop.org/portland/portland/xdg-utils/scripts/xdg-email.in?view=log</ref>
      <ref url="http://webcvs.freedesktop.org/portland/portland/xdg-utils/scripts/xdg-email.in?r1=1.24&amp;r2=1.25" source="CONFIRM">http://webcvs.freedesktop.org/portland/portland/xdg-utils/scripts/xdg-email.in?r1=1.24&amp;r2=1.25</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200801-21.xml" source="GENTOO">GLSA-200801-21</ref>
      <ref url="http://secunia.com/advisories/28728" source="SECUNIA" adv="1">28728</ref>
      <ref url="http://secunia.com/advisories/28638" source="SECUNIA" adv="1">28638</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=207331" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=207331</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:031" source="MANDRIVA">MDVSA-2008:031</ref>
      <ref url="http://secunia.com/advisories/29048" source="SECUNIA">29048</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00008.html" source="SUSE">SUSE-SR:2008:004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gentoo" name="xdg-utils">
        <vers prev="1" num="1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0387" published="2008-01-28" name="CVE-2008-0387" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers to execute arbitrary code via crafted (1) op_receive, (2) op_start, (3) op_start_and_receive, (4) op_send, (5) op_start_and_send, and (6) op_start_send_and_receive XDR requests, which triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.coresecurity.com/?action=item&amp;id=2095" source="MISC" patch="1">http://www.coresecurity.com/?action=item&amp;id=2095</ref>
      <ref url="http://www.securityfocus.com/bid/27403" source="BID">27403</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487173/100/0/threaded" source="BUGTRAQ">20080128 CORE-2007-1219: Firebird Remote Memory Corruption</ref>
      <ref url="http://tracker.firebirdsql.org/browse/CORE-1681" source="CONFIRM">http://tracker.firebirdsql.org/browse/CORE-1681</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39996" source="XF">firebird-xdrprotocol-integer-overflow(39996)</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1529" source="DEBIAN">DSA-1529</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=9028&amp;release_id=570800" source="CONFIRM">http://sourceforge.net/project/shownotes.php?group_id=9028&amp;release_id=570800</ref>
      <ref url="http://securityreason.com/securityalert/3580" source="SREASON">3580</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200803-02.xml" source="GENTOO">GLSA-200803-02</ref>
      <ref url="http://secunia.com/advisories/29501" source="SECUNIA">29501</ref>
      <ref url="http://secunia.com/advisories/29203" source="SECUNIA">29203</ref>
    </refs>
    <vuln_soft>
      <prod vendor="firebirdsql" name="firebird">
        <vers prev="1" num="1.0.3"/>
        <vers prev="1" num="1.5.5"/>
        <vers prev="1" num="2.0.3"/>
        <vers prev="1" num="2.1_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0388" published="2008-01-22" name="CVE-2008-0388" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in the WP-Forum 1.7.4 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the user parameter in a showprofile action to the default URI.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39800" source="XF">wpforum-index-sql-injection(39800)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0235" source="VUPEN">ADV-2008-0235</ref>
      <ref url="http://www.securityfocus.com/bid/27362" source="BID">27362</ref>
      <ref url="http://www.milw0rm.com/exploits/4939" source="MILW0RM">4939</ref>
      <ref url="http://secunia.com/advisories/28567" source="SECUNIA" adv="1">28567</ref>
      <ref url="http://osvdb.org/52211" source="OSVDB">52211</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2008-02/0272.html" source="BUGTRAQ">20080216 WordPress forumaction (PAGE_id)(user)SQL Injectio</ref>
      <ref url="http://weblogtoolscollection.com/archives/2008/01/21/wp-forum-plugin-security-bulletin/" source="CONFIRM">http://weblogtoolscollection.com/archives/2008/01/21/wp-forum-plugin-security-bulletin/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wp_forum">
        <vers num="1.7.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0389" published="2008-01-22" name="CVE-2008-0389" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the serveServletsByClassnameEnabled feature in IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.25, 6.1 through 6.1.0.14, and 5.1.1.x before 5.1.1.18 has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27371" source="BID" patch="1">27371</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg24018067" source="CONFIRM" patch="1" adv="1">http://www-1.ibm.com/support/docview.wss?uid=swg24018067</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39808" source="XF">websphere-serveservlets-unspecified(39808)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1133" source="VUPEN" adv="1">ADV-2008-1133</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0219" source="VUPEN" adv="1">ADV-2008-0219</ref>
      <ref url="http://www.securitytracker.com/id?1019894" source="SECTRACK">1019894</ref>
      <ref url="http://www.securitytracker.com/id?1019251" source="SECTRACK">1019251</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg27006879#51118" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg27006879#51118</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg24018067" source="AIXAPAR">PK52059</ref>
      <ref url="http://secunia.com/advisories/29687" source="SECUNIA" adv="1">29687</ref>
      <ref url="http://secunia.com/advisories/28576" source="SECUNIA" adv="1">28576</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="5.1.1"/>
        <vers num="5.1.1.1"/>
        <vers num="5.1.1.10"/>
        <vers num="5.1.1.12"/>
        <vers num="5.1.1.14"/>
        <vers num="5.1.1.15"/>
        <vers num="5.1.1.16"/>
        <vers prev="1" num="5.1.1.17"/>
        <vers num="5.1.1.2"/>
        <vers num="5.1.1.3"/>
        <vers num="5.1.1.4"/>
        <vers num="5.1.1.5"/>
        <vers num="5.1.1.6"/>
        <vers num="5.1.1.7"/>
        <vers num="5.1.1.8"/>
        <vers num="5.1.1.9"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2" edition=""/>
        <vers num="6.0.2" edition=":fp17"/>
        <vers num="6.0.2.1"/>
        <vers num="6.0.2.11"/>
        <vers num="6.0.2.13"/>
        <vers num="6.0.2.19"/>
        <vers num="6.0.2.22"/>
        <vers num="6.0.2.23"/>
        <vers num="6.0.2.24"/>
        <vers num="6.0.2.25"/>
        <vers num="6.0.2.3"/>
        <vers num="6.0.2.5"/>
        <vers num="6.0.2.7"/>
        <vers num="6.0.2.9"/>
        <vers num="6.1"/>
        <vers num="6.1.1"/>
        <vers num="6.1.13"/>
        <vers num="6.1.14"/>
        <vers num="6.1.3"/>
        <vers num="6.1.5"/>
        <vers num="6.1.6"/>
        <vers num="6.1.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0390" published="2008-01-22" name="CVE-2008-0390" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">stat.php in AuraCMS 1.62, and Mod Block Statistik for AuraCMS, allows remote attackers to inject arbitrary PHP code into online.db.txt via the X-Forwarded-For HTTP header in a stat action to index.php, and execute online.db.txt via a certain request to index.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27342" source="BID">27342</ref>
      <ref url="http://www.milw0rm.com/exploits/4933" source="MILW0RM">4933</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39777" source="XF">auracms-stat-code-execution(39777)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="auracms" name="auracms">
        <vers num="1.62"/>
      </prod>
      <prod vendor="auracms" name="mod_block_statistik">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0391" published="2008-01-22" name="CVE-2008-0391" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">inc/elementz.php in aliTalk 1.9.1.1 does not properly verify authentication, which allows remote attackers to add an arbitrary user account via a modified lilil parameter, in conjunction with the ubild and pa parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27315" source="BID">27315</ref>
      <ref url="http://www.milw0rm.com/exploits/4922" source="MILW0RM">4922</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alilg" name="alitalk">
        <vers num="1.9.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0392" published="2008-01-22" name="CVE-2008-0392" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple buffer overflows in Microsoft Visual Basic Enterprise Edition 6.0 SP6 allow user-assisted remote attackers to execute arbitrary code via a .dsr file with a long (1) ConnectionName or (2) CommandName line.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39773" source="XF">visualbasic-enterprise-dsr-bo(39773)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0195" source="VUPEN">ADV-2008-0195</ref>
      <ref url="http://www.securityfocus.com/bid/27349" source="BID">27349</ref>
      <ref url="http://www.milw0rm.com/exploits/4938" source="MILW0RM">4938</ref>
      <ref url="http://www.securitytracker.com/id?1019258" source="SECTRACK">1019258</ref>
      <ref url="http://secunia.com/advisories/28563" source="SECUNIA">28563</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visual_basic">
        <vers num="6.0" edition="sp6"/>
        <vers num="6.0" edition="sp6:enterprise"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0393" published="2008-01-22" name="CVE-2008-0393" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in info.php in GradMan 0.1.3 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tabla parameter, a different vector than CVE-2008-0361.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39768" source="XF">gradman-info-file-include(39768)</ref>
      <ref url="http://www.securityfocus.com/bid/27343" source="BID">27343</ref>
      <ref url="http://www.milw0rm.com/exploits/4936" source="MILW0RM">4936</ref>
      <ref url="http://secunia.com/advisories/28520" source="SECUNIA" adv="1">28520</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gradman" name="gradman">
        <vers prev="1" num="0.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0394" published="2008-01-23" name="CVE-2008-0394" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Citadel SMTP server 7.10 and earlier allows remote attackers to execute arbitrary code via a long RCPT TO command, which is not properly handled by the makeuserkey function.  NOTE: some of these details were obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39807" source="XF">citadel-makeuserkey-bo(39807)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0252" source="VUPEN">ADV-2008-0252</ref>
      <ref url="http://www.milw0rm.com/sploits/2008-vs-GNU-citadel.tar.gz" source="MISC">http://www.milw0rm.com/sploits/2008-vs-GNU-citadel.tar.gz</ref>
      <ref url="http://www.milw0rm.com/exploits/4949" source="MILW0RM">4949</ref>
      <ref url="http://secunia.com/advisories/28590" source="SECUNIA" adv="1">28590</ref>
      <ref url="http://www.securitytracker.com/id?1019255" source="SECTRACK">1019255</ref>
      <ref url="http://www.securityfocus.com/bid/27376" source="BID">27376</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citadel" name="smtp">
        <vers prev="1" num="7.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0395" published="2008-01-23" name="CVE-2008-0395" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Kayako SupportSuite 3.11.01 allows remote attackers to obtain server configuration information via a direct request to syncml/index.php, which prints the contents of the $_SERVER superglobal.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.waraxe.us/advisory-63.html" source="MISC">http://www.waraxe.us/advisory-63.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486762/100/0/threaded" source="BUGTRAQ">20080121 [waraxe-2008-SA#063] - Information Leakage in Kayako SupportSuite 3.11.01</ref>
      <ref url="http://secunia.com/advisories/28613" source="SECUNIA" adv="1">28613</ref>
      <ref url="http://securityreason.com/securityalert/3573" source="SREASON">3573</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kayako" name="supportsuite">
        <vers num="3.11.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0396" published="2008-01-23" name="CVE-2008-0396" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in BitDefender Update Server (http.exe), as used in BitDefender products including Security for Fileservers and Enterprise Manager (BDEM), allows remote attackers to read arbitrary files via .. (dot dot) sequences in an HTTP request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39802" source="XF">bitdefender-http-server-directory-traversal(39802)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0213" source="VUPEN">ADV-2008-0213</ref>
      <ref url="http://www.securityfocus.com/bid/27358" source="BID">27358</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486701/100/0/threaded" source="BUGTRAQ">20080119 BitDefender Update Server - Unauthorized Remote File Access Vulnerability</ref>
      <ref url="http://www.oliverkarow.de/research/bitdefender.txt" source="MISC">http://www.oliverkarow.de/research/bitdefender.txt</ref>
      <ref url="http://secunia.com/advisories/28578" source="SECUNIA" adv="1">28578</ref>
      <ref url="http://oliver.greyhat.de/2008/01/19/bitdefender-unauthorized-remote-file-access-vulnerability/" source="MISC">http://oliver.greyhat.de/2008/01/19/bitdefender-unauthorized-remote-file-access-vulnerability/</ref>
      <ref url="http://securityreason.com/securityalert/3568" source="SREASON">3568</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bitdefender" name="update_server">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0397" published="2008-01-23" name="CVE-2008-0397" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in aflog 1.01, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to comments.php and (2) an unspecified parameter to view.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0255" source="VUPEN">ADV-2008-0255</ref>
      <ref url="http://www.securityfocus.com/bid/27398" source="BID">27398</ref>
      <ref url="http://www.milw0rm.com/exploits/4958" source="MILW0RM">4958</ref>
      <ref url="http://secunia.com/advisories/28594" source="SECUNIA">28594</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aflog.org" name="aflog">
        <vers num="1.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0398" published="2008-01-23" name="CVE-2008-0398" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in aflog 1.01, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the comment form.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0255" source="VUPEN">ADV-2008-0255</ref>
      <ref url="http://www.securityfocus.com/bid/27398" source="BID">27398</ref>
      <ref url="http://www.milw0rm.com/exploits/4958" source="MILW0RM">4958</ref>
      <ref url="http://secunia.com/advisories/28594" source="SECUNIA">28594</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aflog" name="aflog">
        <vers prev="1" num="1.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0399" published="2008-01-23" name="CVE-2008-0399" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple buffer overflows in Toshiba Surveillance (Surveillix) RecordSend ActiveX control (MeIpCamX.DLL 1.0.0.4) allow remote attackers to execute arbitrary code via long arguments to the (1) SetPort and (2) SetIpAddress methods.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39792" source="XF">toshiba-recordsend-bo(39792)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0214" source="VUPEN">ADV-2008-0214</ref>
      <ref url="http://www.securityfocus.com/bid/27360" source="BID">27360</ref>
      <ref url="http://www.milw0rm.com/exploits/4946" source="MILW0RM">4946</ref>
      <ref url="http://secunia.com/advisories/28557" source="SECUNIA" adv="1">28557</ref>
      <ref url="http://retrogod.altervista.org/rgod_toshiba_control.html" source="MISC">http://retrogod.altervista.org/rgod_toshiba_control.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="toshiba" name="surveillix">
        <vers num="1.0.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0400" published="2008-01-23" name="CVE-2008-0400" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in header.tpl.php in the modern template for Singapore 0.10.1 allows remote attackers to inject arbitrary web script or HTML via the gallery parameter to default.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0234" source="VUPEN">ADV-2008-0234</ref>
      <ref url="http://www.securityfocus.com/bid/27382" source="BID">27382</ref>
      <ref url="http://trew.icenetx.net/toolz/advisory-singapore-modern-template.txt" source="MISC">http://trew.icenetx.net/toolz/advisory-singapore-modern-template.txt</ref>
      <ref url="http://secunia.com/advisories/28573" source="SECUNIA" adv="1">28573</ref>
    </refs>
    <vuln_soft>
      <prod vendor="modern" name="modern">
        <vers num="1.3.2"/>
      </prod>
      <prod vendor="singapore" name="singapore">
        <vers num="0.10.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0401" published="2008-01-23" name="CVE-2008-0401" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the logging functionality of the HTTP server in IBM Tivoli Provisioning Manager for OS Deployment (TPMfOSD) before 5.1.0.3 Interim Fix 3 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via an HTTP request with a long method string to port 443/tcp.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/158609" source="CERT-VN">VU#158609</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg24018010" source="CONFIRM" patch="1">http://www-1.ibm.com/support/docview.wss?uid=swg24018010</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39819" source="XF">tivoli-provisioning-http-unspecified(39819)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0239" source="VUPEN">ADV-2008-0239</ref>
      <ref url="http://www.securitytracker.com/id?1019249" source="SECTRACK">1019249</ref>
      <ref url="http://www.securityfocus.com/bid/27387" source="BID">27387</ref>
      <ref url="http://secunia.com/advisories/28604" source="SECUNIA" adv="1">28604</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=647" source="IDEFENSE">20080122 IBM Tivoli PMfOSD HTTP Request Method Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_provisioning_manager_os_deployment">
        <vers prev="1" num="5.1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0402" published="2008-01-23" name="CVE-2008-0402" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in IBM WebSphere Business Modeler Basic and Advanced 6.0.2.1 before Interim Fix 11 allows remote authenticated users to bypass intended access restrictions and delete unspecified repository resources via unknown vectors, even when they are not administrators or members of the repository's owning group.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg24018061" source="CONFIRM" patch="1">http://www-1.ibm.com/support/docview.wss?uid=swg24018061</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg24018060" source="CONFIRM" patch="1">http://www-1.ibm.com/support/docview.wss?uid=swg24018060</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39830" source="XF">websphere-repository-weak-security(39830)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0254" source="VUPEN">ADV-2008-0254</ref>
      <ref url="http://www.securitytracker.com/id?1019252" source="SECTRACK">1019252</ref>
      <ref url="http://www.securityfocus.com/bid/27389" source="BID">27389</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=JR28175&amp;apar=only" source="AIXAPAR">JR28175</ref>
      <ref url="http://secunia.com/advisories/28586" source="SECUNIA" adv="1">28586</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_business_modeler">
        <vers num="6.0.2_1" edition=""/>
        <vers num="6.0.2_1" edition=":advanced"/>
        <vers num="6.0.2_1" edition=":basic"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0403" published="2008-01-23" name="CVE-2008-0403" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">The web server in Belkin Wireless G Plus MIMO Router F5D9230-4 does not require authentication for SaveCfgFile.cgi, which allows remote attackers to read and modify configuration via a direct request to SaveCfgFile.cgi.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39793" source="XF">belkin-savecfgfile-authentication-bypass(39793)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0215" source="VUPEN">ADV-2008-0215</ref>
      <ref url="http://www.securityfocus.com/bid/27359" source="BID">27359</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486748/100/0/threaded" source="BUGTRAQ">20080119 Belkin Wireless G Plus MIMO Router F5D9230-4 Authentication Bypass Vulnerability</ref>
      <ref url="http://www.milw0rm.com/exploits/4941" source="MILW0RM">4941</ref>
      <ref url="http://securityreason.com/securityalert/3566" source="SREASON">3566</ref>
      <ref url="http://secunia.com/advisories/28554" source="SECUNIA">28554</ref>
    </refs>
    <vuln_soft>
      <prod vendor="belkin" name="f5d9230-4">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0404" published="2008-01-23" name="CVE-2008-0404" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Mantis before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to the "Most active bugs" summary.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27367" source="BID" patch="1">27367</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=569765" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=569765</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00734.html" source="FEDORA">FEDORA-2008-0856</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00676.html" source="FEDORA">FEDORA-2008-0796</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=429552" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=429552</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39801" source="XF">mantis-mostactive-xss(39801)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0232" source="VUPEN">ADV-2008-0232</ref>
      <ref url="http://secunia.com/advisories/28591" source="SECUNIA" adv="1">28591</ref>
      <ref url="http://secunia.com/advisories/28577" source="SECUNIA" adv="1">28577</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mantis" name="mantis">
        <vers num="0.10"/>
        <vers num="0.10.1"/>
        <vers num="0.10.2"/>
        <vers num="0.11"/>
        <vers num="0.11.1"/>
        <vers num="0.12"/>
        <vers num="0.13"/>
        <vers num="0.13.1"/>
        <vers num="0.14"/>
        <vers num="0.14.1"/>
        <vers num="0.14.2"/>
        <vers num="0.14.3"/>
        <vers num="0.14.4"/>
        <vers num="0.14.5"/>
        <vers num="0.14.6"/>
        <vers num="0.14.7"/>
        <vers num="0.14.8"/>
        <vers num="0.15"/>
        <vers num="0.15.1"/>
        <vers num="0.15.10"/>
        <vers num="0.15.11"/>
        <vers num="0.15.12"/>
        <vers num="0.15.2"/>
        <vers num="0.15.3"/>
        <vers num="0.15.4"/>
        <vers num="0.15.5"/>
        <vers num="0.15.6"/>
        <vers num="0.15.7"/>
        <vers num="0.15.8"/>
        <vers num="0.15.9"/>
        <vers num="0.16"/>
        <vers num="0.16.0"/>
        <vers num="0.16.1"/>
        <vers num="0.17"/>
        <vers num="0.17.0"/>
        <vers num="0.17.1"/>
        <vers num="0.17.2"/>
        <vers num="0.17.3"/>
        <vers num="0.17.4"/>
        <vers num="0.17.4a"/>
        <vers num="0.17.5"/>
        <vers num="0.18"/>
        <vers num="0.18.0"/>
        <vers num="0.18.0_rc1"/>
        <vers num="0.18.0a2"/>
        <vers num="0.18.0a3"/>
        <vers num="0.18.0a4"/>
        <vers num="0.18.2"/>
        <vers num="0.18.3"/>
        <vers num="0.18a1"/>
        <vers num="0.19.0"/>
        <vers num="0.19.0_rc1"/>
        <vers num="0.19.0a"/>
        <vers num="0.19.0a1"/>
        <vers num="0.19.0a2"/>
        <vers num="0.19.1"/>
        <vers num="0.19.2"/>
        <vers num="0.19.3"/>
        <vers num="0.19.4"/>
        <vers num="0.9"/>
        <vers num="0.9.1"/>
        <vers num="1.0"/>
        <vers num="1.0.0_rc1"/>
        <vers num="1.0.0_rc2"/>
        <vers num="1.0.0_rc3"/>
        <vers num="1.0.0_rc4"/>
        <vers num="1.0.0a1"/>
        <vers num="1.0.0a2"/>
        <vers num="1.0.0a3"/>
        <vers num="1.0.1"/>
        <vers num="1.1"/>
        <vers prev="1" num="1.1.0"/>
        <vers num="1.1.0a1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0405" published="2008-01-28" name="CVE-2008-0405" modified="2009-09-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allow remote attackers to create arbitrary (1) files and (2) directories via a .. (dot dot) in an account name, when requesting the / URI; and (3) append arbitrary data to a file via a .. (dot dot) in an account name, when requesting a URI composed of a "/?%0a" sequence followed by the data.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39873" source="XF">hfs-unspecified-command-execution(39873)</ref>
      <ref url="http://www.syhunt.com/advisories/hfshack.txt" source="MISC">http://www.syhunt.com/advisories/hfshack.txt</ref>
      <ref url="http://www.securityfocus.com/bid/27423" source="BID">27423</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486873/100/0/threaded" source="BUGTRAQ">20080123 Syhunt: HFS (HTTP File Server) Log Arbitrary File/Directory Manipulation and Denial-of-Service Vulnerabilities</ref>
      <ref url="http://www.rejetto.com/hfs/?f=wn" source="MISC">http://www.rejetto.com/hfs/?f=wn</ref>
      <ref url="http://secunia.com/advisories/28631" source="SECUNIA" adv="1">28631</ref>
      <ref url="http://securityreason.com/securityalert/3581" source="SREASON">3581</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hfs" name="http_file_server">
        <vers prev="1" num="2.2b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0406" published="2008-01-28" name="CVE-2008-0406" modified="2009-09-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allows remote attackers to cause a denial of service (daemon crash) via a long account name.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39875" source="XF">hfs-filename-dos(39875)</ref>
      <ref url="http://www.syhunt.com/advisories/hfshack.txt" source="MISC">http://www.syhunt.com/advisories/hfshack.txt</ref>
      <ref url="http://www.securityfocus.com/bid/27423" source="BID">27423</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486873/100/0/threaded" source="BUGTRAQ">20080123 Syhunt: HFS (HTTP File Server) Log Arbitrary File/Directory Manipulation and Denial-of-Service Vulnerabilities</ref>
      <ref url="http://www.rejetto.com/hfs/?f=wn" source="MISC">http://www.rejetto.com/hfs/?f=wn</ref>
      <ref url="http://secunia.com/advisories/28631" source="SECUNIA" adv="1">28631</ref>
      <ref url="http://securityreason.com/securityalert/3581" source="SREASON">3581</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hfs" name="http_file_server">
        <vers prev="1" num="2.2b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0407" published="2008-01-28" name="CVE-2008-0407" modified="2009-09-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">HTTP File Server (HFS) before 2.2c tags HTTP request log entries with the username sent during HTTP Basic Authentication, regardless of whether authentication succeeded, which might make it more difficult for an administrator to determine who made a remote request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39877" source="XF">hfs-username-spoofing(39877)</ref>
      <ref url="http://www.syhunt.com/advisories/hfshack.txt" source="MISC">http://www.syhunt.com/advisories/hfshack.txt</ref>
      <ref url="http://www.securityfocus.com/bid/27423" source="BID">27423</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486874/100/0/threaded" source="BUGTRAQ">20080123 Syhunt: HFS (HTTP File Server) Username Spoofing and Log Forging/Injection Vulnerability</ref>
      <ref url="http://www.rejetto.com/hfs/?f=wn" source="MISC">http://www.rejetto.com/hfs/?f=wn</ref>
      <ref url="http://secunia.com/advisories/28631" source="SECUNIA" adv="1">28631</ref>
      <ref url="http://securityreason.com/securityalert/3582" source="SREASON">3582</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hfs" name="http_file_server">
        <vers prev="1" num="2.2b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0408" published="2008-01-28" name="CVE-2008-0408" modified="2009-09-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">HTTP File Server (HFS) before 2.2c allows remote attackers to append arbitrary text to the log file by using the base64 representation of this text during HTTP Basic Authentication.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39876" source="XF">hfs-unspecified-log-injection(39876)</ref>
      <ref url="http://www.syhunt.com/advisories/hfshack.txt" source="MISC">http://www.syhunt.com/advisories/hfshack.txt</ref>
      <ref url="http://www.securityfocus.com/bid/27423" source="BID">27423</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486874/100/0/threaded" source="BUGTRAQ">20080123 Syhunt: HFS (HTTP File Server) Username Spoofing and Log Forging/Injection Vulnerability</ref>
      <ref url="http://www.rejetto.com/hfs/?f=wn" source="MISC">http://www.rejetto.com/hfs/?f=wn</ref>
      <ref url="http://secunia.com/advisories/28631" source="SECUNIA">28631</ref>
      <ref url="http://securityreason.com/securityalert/3582" source="SREASON">3582</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hfs" name="http_file_server">
        <vers prev="1" num="2.2b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0409" published="2008-01-28" name="CVE-2008-0409" modified="2009-09-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in HTTP File Server (HFS) before 2.2c allows remote attackers to inject arbitrary web script or HTML via the userinfo subcomponent of a URL.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39870" source="XF">hfs-host-xss(39870)</ref>
      <ref url="http://www.syhunt.com/advisories/hfshack.txt" source="MISC">http://www.syhunt.com/advisories/hfshack.txt</ref>
      <ref url="http://www.securityfocus.com/bid/27423" source="BID">27423</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486872/100/0/threaded" source="BUGTRAQ">20080123 Syhunt: HFS (HTTP File Server) Template Cross-Site Scripting and Information Disclosure Vulnerabilities</ref>
      <ref url="http://www.rejetto.com/hfs/?f=wn" source="MISC">http://www.rejetto.com/hfs/?f=wn</ref>
      <ref url="http://secunia.com/advisories/28631" source="SECUNIA" adv="1">28631</ref>
      <ref url="http://securityreason.com/securityalert/3583" source="SREASON">3583</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hfs" name="http_file_server">
        <vers prev="1" num="2.2b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0410" published="2008-01-28" name="CVE-2008-0410" modified="2009-09-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">HTTP File Server (HFS) before 2.2c allows remote attackers to obtain configuration and usage details by using an id element such as &lt;id>%version%&lt;/id> in HTTP Basic Authentication instead of a username and password, as demonstrated by placing this id element in the userinfo subcomponent of a URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39871" source="XF">hfs-sendhfsidentifier-info-disclosure(39871)</ref>
      <ref url="http://www.syhunt.com/advisories/hfshack.txt" source="MISC">http://www.syhunt.com/advisories/hfshack.txt</ref>
      <ref url="http://www.securityfocus.com/bid/27423" source="BID">27423</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486872/100/0/threaded" source="BUGTRAQ">20080123 Syhunt: HFS (HTTP File Server) Template Cross-Site Scripting and Information Disclosure Vulnerabilities</ref>
      <ref url="http://www.rejetto.com/hfs/?f=wn" source="MISC">http://www.rejetto.com/hfs/?f=wn</ref>
      <ref url="http://secunia.com/advisories/28631" source="SECUNIA" adv="1">28631</ref>
      <ref url="http://securityreason.com/securityalert/3583" source="SREASON">3583</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hfs" name="http_file_server">
        <vers prev="1" num="2.2b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0411" published="2008-02-28" name="CVE-2008-0411" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code via a postscript (.ps) file containing a long Range array in a .seticcspace operator.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2008/dsa-1510" source="DEBIAN" patch="1">DSA-1510</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00085.html" source="FEDORA">FEDORA-2008-1998</ref>
      <ref url="https://issues.rpath.com/browse/RPL-2217" source="CONFIRM">https://issues.rpath.com/browse/RPL-2217</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0693/references" source="VUPEN">ADV-2008-0693</ref>
      <ref url="http://www.ubuntu.com/usn/usn-599-1" source="UBUNTU">USN-599-1</ref>
      <ref url="http://www.securitytracker.com/id?1019511" source="SECTRACK">1019511</ref>
      <ref url="http://www.securityfocus.com/bid/28017" source="BID">28017</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488946/100/0/threaded" source="BUGTRAQ">20080228 Ghostscript buffer overflow</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488932/100/0/threaded" source="BUGTRAQ">20080228 rPSA-2008-0082-1 espgs</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0155.html" source="REDHAT">RHSA-2008:0155</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:055" source="MANDRIVA">MDVSA-2008:055</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200803-14.xml" source="GENTOO">GLSA-200803-14</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2008-0082" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2008-0082</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2008&amp;m=slackware-security.370633" source="SLACKWARE">SSA:2008-062-01</ref>
      <ref url="http://secunia.com/advisories/29768" source="SECUNIA">29768</ref>
      <ref url="http://secunia.com/advisories/29314" source="SECUNIA">29314</ref>
      <ref url="http://secunia.com/advisories/29196" source="SECUNIA">29196</ref>
      <ref url="http://secunia.com/advisories/29169" source="SECUNIA">29169</ref>
      <ref url="http://secunia.com/advisories/29154" source="SECUNIA">29154</ref>
      <ref url="http://secunia.com/advisories/29147" source="SECUNIA">29147</ref>
      <ref url="http://secunia.com/advisories/29135" source="SECUNIA">29135</ref>
      <ref url="http://secunia.com/advisories/29112" source="SECUNIA">29112</ref>
      <ref url="http://secunia.com/advisories/29103" source="SECUNIA">29103</ref>
      <ref url="http://secunia.com/advisories/29101" source="SECUNIA">29101</ref>
      <ref url="http://scary.beasts.org/security/CESA-2008-001.html" source="MISC">http://scary.beasts.org/security/CESA-2008-001.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9557" source="OVAL">oval:org.mitre.oval:def:9557</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00009.html" source="SUSE">SUSE-SA:2008:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ghostscript" name="ghostscript">
        <vers num="0"/>
        <vers num="8.0.1"/>
        <vers num="8.15"/>
        <vers prev="1" num="8.61"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0412" published="2008-02-08" name="CVE-2008-0412" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The browser engine in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via vectors related to the (1) nsTableFrame::GetFrameAtOrBefore, (2) nsAccessibilityService::GetAccessible, (3) nsBindingManager::GetNestedInsertionPoint, (4) nsXBLPrototypeBinding::AttributeChanged, (5) nsColumnSetFrame::GetContentInsertionFrame, and (6) nsLineLayout::TrimTrailingWhiteSpaceIn methods, and other vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00381.html" source="FEDORA">FEDORA-2008-1535</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00309.html" source="FEDORA">FEDORA-2008-1459</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00274.html" source="FEDORA">FEDORA-2008-1435</ref>
      <ref url="https://bugzilla.mozilla.org/buglist.cgi?bug_id=398088,393141,364801,346405,396613,394337,406290" source="CONFIRM">https://bugzilla.mozilla.org/buglist.cgi?bug_id=398088,393141,364801,346405,396613,394337,406290</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/2091/references" source="VUPEN">ADV-2008-2091</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1793/references" source="VUPEN">ADV-2008-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0627/references" source="VUPEN">ADV-2008-0627</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0454/references" source="VUPEN">ADV-2008-0454</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0453/references" source="VUPEN">ADV-2008-0453</ref>
      <ref url="http://www.ubuntu.com/usn/usn-576-1" source="UBUNTU">USN-576-1</ref>
      <ref url="http://www.securitytracker.com/id?1019320" source="SECTRACK">1019320</ref>
      <ref url="http://www.securityfocus.com/bid/27683" source="BID">27683</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488002/100/0/threaded" source="BUGTRAQ">20080212 FLEA-2008-0001-1 firefox</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487826/100/0/threaded" source="BUGTRAQ">20080209 rPSA-2008-0051-1 firefox</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0105.html" source="REDHAT">RHSA-2008:0105</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0104.html" source="REDHAT">RHSA-2008:0104</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0103.html" source="REDHAT">RHSA-2008:0103</ref>
      <ref url="http://www.mozilla.org/security/announce/2008/mfsa2008-01.html" source="CONFIRM">http://www.mozilla.org/security/announce/2008/mfsa2008-01.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:048" source="MANDRIVA">MDVSA-2008:048</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml" source="GENTOO">GLSA-200805-18</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1506" source="DEBIAN">DSA-1506</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1489" source="DEBIAN">DSA-1489</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1485" source="DEBIAN">DSA-1485</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1484" source="DEBIAN">DSA-1484</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2008-0051" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2008-0051</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-239546-1" source="SUNALERT">239546</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1" source="SUNALERT">238492</ref>
      <ref url="http://secunia.com/advisories/31043" source="SECUNIA">31043</ref>
      <ref url="http://secunia.com/advisories/30620" source="SECUNIA">30620</ref>
      <ref url="http://secunia.com/advisories/29086" source="SECUNIA">29086</ref>
      <ref url="http://secunia.com/advisories/29049" source="SECUNIA" adv="1">29049</ref>
      <ref url="http://secunia.com/advisories/28958" source="SECUNIA" adv="1">28958</ref>
      <ref url="http://secunia.com/advisories/28939" source="SECUNIA">28939</ref>
      <ref url="http://secunia.com/advisories/28924" source="SECUNIA">28924</ref>
      <ref url="http://secunia.com/advisories/28879" source="SECUNIA" adv="1">28879</ref>
      <ref url="http://secunia.com/advisories/28877" source="SECUNIA" adv="1">28877</ref>
      <ref url="http://secunia.com/advisories/28865" source="SECUNIA" adv="1">28865</ref>
      <ref url="http://secunia.com/advisories/28864" source="SECUNIA" adv="1">28864</ref>
      <ref url="http://secunia.com/advisories/28839" source="SECUNIA" adv="1">28839</ref>
      <ref url="http://secunia.com/advisories/28818" source="SECUNIA" adv="1">28818</ref>
      <ref url="http://secunia.com/advisories/28815" source="SECUNIA" adv="1">28815</ref>
      <ref url="http://secunia.com/advisories/28808" source="SECUNIA" adv="1">28808</ref>
      <ref url="http://secunia.com/advisories/28766" source="SECUNIA" adv="1">28766</ref>
      <ref url="http://secunia.com/advisories/28758" source="SECUNIA" adv="1">28758</ref>
      <ref url="http://secunia.com/advisories/28754" source="SECUNIA" adv="1">28754</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10573" source="OVAL">oval:org.mitre.oval:def:10573</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00006.html" source="SUSE">SUSE-SA:2008:008</ref>
      <ref url="http://browser.netscape.com/releasenotes/" source="CONFIRM">http://browser.netscape.com/releasenotes/</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.html" source="FEDORA">FEDORA-2008-2118</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.html" source="FEDORA">FEDORA-2008-2060</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1995" source="CONFIRM">https://issues.rpath.com/browse/RPL-1995</ref>
      <ref url="http://www.ubuntu.com/usn/usn-582-2" source="UBUNTU">USN-582-2</ref>
      <ref url="http://www.ubuntu.com/usn/usn-582-1" source="UBUNTU">USN-582-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488971/100/0/threaded" source="BUGTRAQ">20080229 rPSA-2008-0093-1 thunderbird</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:062" source="MANDRIVA">MDVSA-2008:062</ref>
      <ref url="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093" source="CONFIRM">http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2008-0093" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2008-0093</ref>
      <ref url="http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html" source="CONFIRM">http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2008&amp;m=slackware-security.445399" source="SLACKWARE">SSA:2008-061-01</ref>
      <ref url="http://secunia.com/advisories/30327" source="SECUNIA">30327</ref>
      <ref url="http://secunia.com/advisories/29567" source="SECUNIA">29567</ref>
      <ref url="http://secunia.com/advisories/29211" source="SECUNIA">29211</ref>
      <ref url="http://secunia.com/advisories/29167" source="SECUNIA">29167</ref>
      <ref url="http://secunia.com/advisories/29164" source="SECUNIA">29164</ref>
      <ref url="http://secunia.com/advisories/29098" source="SECUNIA">29098</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers prev="1" num="2.0.0.11"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.1.7"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers prev="1" num="2.0.0.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0413" published="2008-02-08" name="CVE-2008-0413" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The JavaScript engine in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via (1) a large switch statement, (2) certain uses of watch and eval, (3) certain uses of the mousedown event listener, and other vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.html" source="FEDORA">FEDORA-2008-2118</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.html" source="FEDORA">FEDORA-2008-2060</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00381.html" source="FEDORA">FEDORA-2008-1535</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00309.html" source="FEDORA">FEDORA-2008-1459</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00274.html" source="FEDORA">FEDORA-2008-1435</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1995" source="CONFIRM">https://issues.rpath.com/browse/RPL-1995</ref>
      <ref url="https://bugzilla.mozilla.org/buglist.cgi?bug_id=407720,390597,373344,398085,406572,391028,406036,402087" source="CONFIRM">https://bugzilla.mozilla.org/buglist.cgi?bug_id=407720,390597,373344,398085,406572,391028,406036,402087</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/2091/references" source="VUPEN">ADV-2008-2091</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1793/references" source="VUPEN">ADV-2008-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0627/references" source="VUPEN">ADV-2008-0627</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0454/references" source="VUPEN">ADV-2008-0454</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0453/references" source="VUPEN">ADV-2008-0453</ref>
      <ref url="http://www.ubuntu.com/usn/usn-582-1" source="UBUNTU">USN-582-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-576-1" source="UBUNTU">USN-576-1</ref>
      <ref url="http://www.securitytracker.com/id?1019321" source="SECTRACK">1019321</ref>
      <ref url="http://www.securityfocus.com/bid/27683" source="BID">27683</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488971/100/0/threaded" source="BUGTRAQ">20080229 rPSA-2008-0093-1 thunderbird</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488002/100/0/threaded" source="BUGTRAQ">20080212 FLEA-2008-0001-1 firefox</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487826/100/0/threaded" source="BUGTRAQ">20080209 rPSA-2008-0051-1 firefox</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0105.html" source="REDHAT">RHSA-2008:0105</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0104.html" source="REDHAT">RHSA-2008:0104</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0103.html" source="REDHAT">RHSA-2008:0103</ref>
      <ref url="http://www.mozilla.org/security/announce/2008/mfsa2008-01.html" source="CONFIRM">http://www.mozilla.org/security/announce/2008/mfsa2008-01.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:062" source="MANDRIVA">MDVSA-2008:062</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:048" source="MANDRIVA">MDVSA-2008:048</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml" source="GENTOO">GLSA-200805-18</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1506" source="DEBIAN">DSA-1506</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1489" source="DEBIAN">DSA-1489</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1485" source="DEBIAN">DSA-1485</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1484" source="DEBIAN">DSA-1484</ref>
      <ref url="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093" source="CONFIRM">http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2008-0093" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2008-0093</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2008-0051" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2008-0051</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-239546-1" source="SUNALERT">239546</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1" source="SUNALERT">238492</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2008&amp;m=slackware-security.445399" source="SLACKWARE">SSA:2008-061-01</ref>
      <ref url="http://secunia.com/advisories/31043" source="SECUNIA">31043</ref>
      <ref url="http://secunia.com/advisories/30620" source="SECUNIA">30620</ref>
      <ref url="http://secunia.com/advisories/29167" source="SECUNIA">29167</ref>
      <ref url="http://secunia.com/advisories/29086" source="SECUNIA">29086</ref>
      <ref url="http://secunia.com/advisories/29049" source="SECUNIA">29049</ref>
      <ref url="http://secunia.com/advisories/28958" source="SECUNIA">28958</ref>
      <ref url="http://secunia.com/advisories/28939" source="SECUNIA">28939</ref>
      <ref url="http://secunia.com/advisories/28924" source="SECUNIA">28924</ref>
      <ref url="http://secunia.com/advisories/28879" source="SECUNIA">28879</ref>
      <ref url="http://secunia.com/advisories/28877" source="SECUNIA">28877</ref>
      <ref url="http://secunia.com/advisories/28865" source="SECUNIA">28865</ref>
      <ref url="http://secunia.com/advisories/28864" source="SECUNIA">28864</ref>
      <ref url="http://secunia.com/advisories/28839" source="SECUNIA">28839</ref>
      <ref url="http://secunia.com/advisories/28818" source="SECUNIA">28818</ref>
      <ref url="http://secunia.com/advisories/28815" source="SECUNIA">28815</ref>
      <ref url="http://secunia.com/advisories/28808" source="SECUNIA">28808</ref>
      <ref url="http://secunia.com/advisories/28766" source="SECUNIA">28766</ref>
      <ref url="http://secunia.com/advisories/28758" source="SECUNIA">28758</ref>
      <ref url="http://secunia.com/advisories/28754" source="SECUNIA">28754</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10385" source="OVAL">oval:org.mitre.oval:def:10385</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00006.html" source="SUSE">SUSE-SA:2008:008</ref>
      <ref url="http://browser.netscape.com/releasenotes/" source="CONFIRM">http://browser.netscape.com/releasenotes/</ref>
      <ref url="http://www.ubuntu.com/usn/usn-582-2" source="UBUNTU">USN-582-2</ref>
      <ref url="http://secunia.com/advisories/30327" source="SECUNIA">30327</ref>
      <ref url="http://secunia.com/advisories/29211" source="SECUNIA">29211</ref>
      <ref url="http://secunia.com/advisories/29164" source="SECUNIA">29164</ref>
      <ref url="http://secunia.com/advisories/29098" source="SECUNIA">29098</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers prev="1" num="2.0.0.11"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.1.7"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers prev="1" num="2.0.0.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0414" published="2008-02-08" name="CVE-2008-0414" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8 allows user-assisted remote attackers to trick the user into uploading arbitrary files via label tags that shift focus to a file input field, aka "focus spoofing."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/buglist.cgi?bug_id=404451,408034,404391,405299" source="CONFIRM">https://bugzilla.mozilla.org/buglist.cgi?bug_id=404451,408034,404391,405299</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1793/references" source="VUPEN">ADV-2008-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0627/references" source="VUPEN">ADV-2008-0627</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0453/references" source="VUPEN">ADV-2008-0453</ref>
      <ref url="http://www.mozilla.org/security/announce/2008/mfsa2008-02.html" source="CONFIRM">http://www.mozilla.org/security/announce/2008/mfsa2008-02.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml" source="GENTOO">GLSA-200805-18</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1" source="SUNALERT">238492</ref>
      <ref url="http://secunia.com/advisories/30620" source="SECUNIA">30620</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00381.html" source="FEDORA">FEDORA-2008-1535</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00309.html" source="FEDORA">FEDORA-2008-1459</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00274.html" source="FEDORA">FEDORA-2008-1435</ref>
      <ref url="http://www.ubuntu.com/usn/usn-576-1" source="UBUNTU">USN-576-1</ref>
      <ref url="http://www.securitytracker.com/id?1019330" source="SECTRACK">1019330</ref>
      <ref url="http://www.securityfocus.com/bid/27683" source="BID">27683</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488002/100/0/threaded" source="BUGTRAQ">20080212 FLEA-2008-0001-1 firefox</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487826/100/0/threaded" source="BUGTRAQ">20080209 rPSA-2008-0051-1 firefox</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:048" source="MANDRIVA">MDVSA-2008:048</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1506" source="DEBIAN">DSA-1506</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1489" source="DEBIAN">DSA-1489</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1485" source="DEBIAN">DSA-1485</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1484" source="DEBIAN">DSA-1484</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2008-0051" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2008-0051</ref>
      <ref url="http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html" source="CONFIRM">http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html</ref>
      <ref url="http://secunia.com/advisories/30327" source="SECUNIA">30327</ref>
      <ref url="http://secunia.com/advisories/29567" source="SECUNIA">29567</ref>
      <ref url="http://secunia.com/advisories/29086" source="SECUNIA">29086</ref>
      <ref url="http://secunia.com/advisories/29049" source="SECUNIA">29049</ref>
      <ref url="http://secunia.com/advisories/28958" source="SECUNIA">28958</ref>
      <ref url="http://secunia.com/advisories/28939" source="SECUNIA">28939</ref>
      <ref url="http://secunia.com/advisories/28924" source="SECUNIA">28924</ref>
      <ref url="http://secunia.com/advisories/28879" source="SECUNIA">28879</ref>
      <ref url="http://secunia.com/advisories/28877" source="SECUNIA">28877</ref>
      <ref url="http://secunia.com/advisories/28865" source="SECUNIA">28865</ref>
      <ref url="http://secunia.com/advisories/28864" source="SECUNIA">28864</ref>
      <ref url="http://secunia.com/advisories/28839" source="SECUNIA">28839</ref>
      <ref url="http://secunia.com/advisories/28815" source="SECUNIA">28815</ref>
      <ref url="http://secunia.com/advisories/28758" source="SECUNIA">28758</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00006.html" source="SUSE">SUSE-SA:2008:008</ref>
      <ref url="http://browser.netscape.com/releasenotes/" source="CONFIRM">http://browser.netscape.com/releasenotes/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers prev="1" num="2.0.0.11"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.1.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0415" published="2008-02-08" name="CVE-2008-0415" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to execute script outside of the sandbox and conduct cross-site scripting (XSS) attacks via multiple vectors including the XMLDocument.load function, aka "JavaScript privilege escalation bugs."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/buglist.cgi?bug_id=386695,393761,393762,399298,407289,372075,363597" source="CONFIRM">https://bugzilla.mozilla.org/buglist.cgi?bug_id=386695,393761,393762,399298,407289,372075,363597</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/2091/references" source="VUPEN">ADV-2008-2091</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1793/references" source="VUPEN">ADV-2008-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0627/references" source="VUPEN">ADV-2008-0627</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0454/references" source="VUPEN">ADV-2008-0454</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0453/references" source="VUPEN">ADV-2008-0453</ref>
      <ref url="http://www.mozilla.org/security/announce/2008/mfsa2008-03.html" source="CONFIRM">http://www.mozilla.org/security/announce/2008/mfsa2008-03.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml" source="GENTOO">GLSA-200805-18</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-239546-1" source="SUNALERT">239546</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1" source="SUNALERT">238492</ref>
      <ref url="http://secunia.com/advisories/31043" source="SECUNIA">31043</ref>
      <ref url="http://secunia.com/advisories/30620" source="SECUNIA">30620</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9897" source="OVAL">oval:org.mitre.oval:def:9897</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.html" source="FEDORA">FEDORA-2008-2118</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.html" source="FEDORA">FEDORA-2008-2060</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00381.html" source="FEDORA">FEDORA-2008-1535</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00309.html" source="FEDORA">FEDORA-2008-1459</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00274.html" source="FEDORA">FEDORA-2008-1435</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1995" source="CONFIRM">https://issues.rpath.com/browse/RPL-1995</ref>
      <ref url="http://www.ubuntu.com/usn/usn-582-2" source="UBUNTU">USN-582-2</ref>
      <ref url="http://www.ubuntu.com/usn/usn-582-1" source="UBUNTU">USN-582-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-576-1" source="UBUNTU">USN-576-1</ref>
      <ref url="http://www.securitytracker.com/id?1019327" source="SECTRACK">1019327</ref>
      <ref url="http://www.securityfocus.com/bid/27683" source="BID">27683</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488971/100/0/threaded" source="BUGTRAQ">20080229 rPSA-2008-0093-1 thunderbird</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488002/100/0/threaded" source="BUGTRAQ">20080212 FLEA-2008-0001-1 firefox</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487826/100/0/threaded" source="BUGTRAQ">20080209 rPSA-2008-0051-1 firefox</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0105.html" source="REDHAT">RHSA-2008:0105</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0104.html" source="REDHAT">RHSA-2008:0104</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0103.html" source="REDHAT">RHSA-2008:0103</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:062" source="MANDRIVA">MDVSA-2008:062</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:048" source="MANDRIVA">MDVSA-2008:048</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1506" source="DEBIAN">DSA-1506</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1489" source="DEBIAN">DSA-1489</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1485" source="DEBIAN">DSA-1485</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1484" source="DEBIAN">DSA-1484</ref>
      <ref url="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093" source="CONFIRM">http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2008-0093" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2008-0093</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2008-0051" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2008-0051</ref>
      <ref url="http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html" source="CONFIRM">http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2008&amp;m=slackware-security.445399" source="SLACKWARE">SSA:2008-061-01</ref>
      <ref url="http://secunia.com/advisories/30327" source="SECUNIA">30327</ref>
      <ref url="http://secunia.com/advisories/29567" source="SECUNIA">29567</ref>
      <ref url="http://secunia.com/advisories/29211" source="SECUNIA">29211</ref>
      <ref url="http://secunia.com/advisories/29167" source="SECUNIA">29167</ref>
      <ref url="http://secunia.com/advisories/29164" source="SECUNIA">29164</ref>
      <ref url="http://secunia.com/advisories/29098" source="SECUNIA">29098</ref>
      <ref url="http://secunia.com/advisories/29086" source="SECUNIA">29086</ref>
      <ref url="http://secunia.com/advisories/29049" source="SECUNIA">29049</ref>
      <ref url="http://secunia.com/advisories/28958" source="SECUNIA">28958</ref>
      <ref url="http://secunia.com/advisories/28939" source="SECUNIA">28939</ref>
      <ref url="http://secunia.com/advisories/28924" source="SECUNIA">28924</ref>
      <ref url="http://secunia.com/advisories/28879" source="SECUNIA">28879</ref>
      <ref url="http://secunia.com/advisories/28877" source="SECUNIA">28877</ref>
      <ref url="http://secunia.com/advisories/28865" source="SECUNIA">28865</ref>
      <ref url="http://secunia.com/advisories/28864" source="SECUNIA">28864</ref>
      <ref url="http://secunia.com/advisories/28839" source="SECUNIA">28839</ref>
      <ref url="http://secunia.com/advisories/28818" source="SECUNIA">28818</ref>
      <ref url="http://secunia.com/advisories/28815" source="SECUNIA">28815</ref>
      <ref url="http://secunia.com/advisories/28808" source="SECUNIA">28808</ref>
      <ref url="http://secunia.com/advisories/28766" source="SECUNIA">28766</ref>
      <ref url="http://secunia.com/advisories/28758" source="SECUNIA">28758</ref>
      <ref url="http://secunia.com/advisories/28754" source="SECUNIA">28754</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00006.html" source="SUSE">SUSE-SA:2008:008</ref>
      <ref url="http://browser.netscape.com/releasenotes/" source="CONFIRM">http://browser.netscape.com/releasenotes/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers prev="1" num="2.0.0.11"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.1.7"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers prev="1" num="2.0.0.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0416" published="2008-02-11" name="CVE-2008-0416" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allow remote attackers to inject arbitrary web script or HTML via certain character encodings, including (1) a backspace character that is treated as whitespace, (2) 0x80 with Shift_JIS encoding, and (3) "zero-length non-ASCII sequences" in certain Asian character sets.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-087A.html" source="CERT">TA08-087A</ref>
      <ref url="https://bugzilla.mozilla.org/buglist.cgi?bug_id=404252,381412,407161" source="MISC">https://bugzilla.mozilla.org/buglist.cgi?bug_id=404252,381412,407161</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40488" source="XF">firefox-character-encoding-xss(40488)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/2091/references" source="VUPEN" adv="1">ADV-2008-2091</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1793/references" source="VUPEN" adv="1">ADV-2008-1793</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-576-1" source="UBUNTU">USN-576-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-592-1" source="UBUNTU">USN-592-1</ref>
      <ref url="http://www.turbolinux.com/security/2008/TLSA-2008-9.txt" source="TURBO">TLSA-2008-9</ref>
      <ref url="http://www.securityfocus.com/bid/29303" source="BID">29303</ref>
      <ref url="http://www.mozilla.org/security/announce/2008/mfsa2008-13.html" source="CONFIRM">http://www.mozilla.org/security/announce/2008/mfsa2008-13.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml" source="GENTOO">GLSA-200805-18</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1489" source="DEBIAN">DSA-1489</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1485" source="DEBIAN">DSA-1485</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1484" source="DEBIAN">DSA-1484</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-239546-1" source="SUNALERT">239546</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1" source="SUNALERT">238492</ref>
      <ref url="http://secunia.com/advisories/31043" source="SECUNIA" adv="1">31043</ref>
      <ref url="http://secunia.com/advisories/30620" source="SECUNIA" adv="1">30620</ref>
      <ref url="http://secunia.com/advisories/30327" source="SECUNIA" adv="1">30327</ref>
      <ref url="http://secunia.com/advisories/29541" source="SECUNIA" adv="1">29541</ref>
      <ref url="http://secunia.com/advisories/28879" source="SECUNIA" adv="1">28879</ref>
      <ref url="http://secunia.com/advisories/28865" source="SECUNIA" adv="1">28865</ref>
      <ref url="http://secunia.com/advisories/28864" source="SECUNIA" adv="1">28864</ref>
      <ref url="http://secunia.com/advisories/28839" source="SECUNIA" adv="1">28839</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000021.html" source="JVNDB">JVNDB-2008-000021</ref>
      <ref url="http://jvn.jp/en/jp/JVN21563357/index.html" source="JVN">JVN#21563357</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers prev="1" num="2.0.0.11"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.1.7"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers prev="1" num="2.0.0.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0417" published="2008-02-08" name="CVE-2008-0417" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">CRLF injection vulnerability in Mozilla Firefox before 2.0.0.12 allows remote user-assisted web sites to corrupt the user's password store via newlines that are not properly handled when the user saves a password.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=394610" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=394610</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1793/references" source="VUPEN">ADV-2008-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0627/references" source="VUPEN">ADV-2008-0627</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0453/references" source="VUPEN">ADV-2008-0453</ref>
      <ref url="http://www.mozilla.org/security/announce/2008/mfsa2008-04.html" source="CONFIRM">http://www.mozilla.org/security/announce/2008/mfsa2008-04.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml" source="GENTOO">GLSA-200805-18</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1" source="SUNALERT">238492</ref>
      <ref url="http://secunia.com/advisories/30620" source="SECUNIA">30620</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11154" source="OVAL">oval:org.mitre.oval:def:11154</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00381.html" source="FEDORA">FEDORA-2008-1535</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00309.html" source="FEDORA">FEDORA-2008-1459</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00274.html" source="FEDORA">FEDORA-2008-1435</ref>
      <ref url="http://www.ubuntu.com/usn/usn-576-1" source="UBUNTU">USN-576-1</ref>
      <ref url="http://www.securitytracker.com/id?1019334" source="SECTRACK">1019334</ref>
      <ref url="http://www.securityfocus.com/bid/27683" source="BID">27683</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488002/100/0/threaded" source="BUGTRAQ">20080212 FLEA-2008-0001-1 firefox</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487826/100/0/threaded" source="BUGTRAQ">20080209 rPSA-2008-0051-1 firefox</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0104.html" source="REDHAT">RHSA-2008:0104</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0103.html" source="REDHAT">RHSA-2008:0103</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:048" source="MANDRIVA">MDVSA-2008:048</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1506" source="DEBIAN">DSA-1506</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1489" source="DEBIAN">DSA-1489</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1485" source="DEBIAN">DSA-1485</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1484" source="DEBIAN">DSA-1484</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2008-0051" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2008-0051</ref>
      <ref url="http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html" source="CONFIRM">http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html</ref>
      <ref url="http://secunia.com/advisories/30327" source="SECUNIA">30327</ref>
      <ref url="http://secunia.com/advisories/29567" source="SECUNIA">29567</ref>
      <ref url="http://secunia.com/advisories/29086" source="SECUNIA">29086</ref>
      <ref url="http://secunia.com/advisories/28958" source="SECUNIA">28958</ref>
      <ref url="http://secunia.com/advisories/28939" source="SECUNIA">28939</ref>
      <ref url="http://secunia.com/advisories/28924" source="SECUNIA">28924</ref>
      <ref url="http://secunia.com/advisories/28879" source="SECUNIA">28879</ref>
      <ref url="http://secunia.com/advisories/28877" source="SECUNIA">28877</ref>
      <ref url="http://secunia.com/advisories/28865" source="SECUNIA">28865</ref>
      <ref url="http://secunia.com/advisories/28864" source="SECUNIA">28864</ref>
      <ref url="http://secunia.com/advisories/28839" source="SECUNIA">28839</ref>
      <ref url="http://secunia.com/advisories/28818" source="SECUNIA">28818</ref>
      <ref url="http://secunia.com/advisories/28766" source="SECUNIA">28766</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00006.html" source="SUSE">SUSE-SA:2008:008</ref>
      <ref url="http://browser.netscape.com/releasenotes/" source="CONFIRM">http://browser.netscape.com/releasenotes/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers prev="1" num="2.0.0.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0418" published="2008-02-08" name="CVE-2008-0418" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8, when using "flat" addons, allows remote attackers to read arbitrary Javascript, image, and stylesheet files via the chrome: URI scheme, as demonstrated by stealing session information from sessionstore.js.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/309608" source="CERT-VN">VU#309608</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/2091/references" source="VUPEN">ADV-2008-2091</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1793/references" source="VUPEN">ADV-2008-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0627/references" source="VUPEN">ADV-2008-0627</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0454/references" source="VUPEN">ADV-2008-0454</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0453/references" source="VUPEN">ADV-2008-0453</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0263" source="VUPEN">ADV-2008-0263</ref>
      <ref url="http://www.mozilla.org/security/announce/2008/mfsa2008-05.html" source="CONFIRM">http://www.mozilla.org/security/announce/2008/mfsa2008-05.html</ref>
      <ref url="http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/" source="MISC">http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml" source="GENTOO">GLSA-200805-18</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-239546-1" source="SUNALERT">239546</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1" source="SUNALERT">238492</ref>
      <ref url="http://secunia.com/advisories/31043" source="SECUNIA">31043</ref>
      <ref url="http://secunia.com/advisories/30620" source="SECUNIA">30620</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10705" source="OVAL">oval:org.mitre.oval:def:10705</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.html" source="FEDORA">FEDORA-2008-2118</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.html" source="FEDORA">FEDORA-2008-2060</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00381.html" source="FEDORA">FEDORA-2008-1535</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00309.html" source="FEDORA">FEDORA-2008-1459</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00274.html" source="FEDORA">FEDORA-2008-1435</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1995" source="CONFIRM">https://issues.rpath.com/browse/RPL-1995</ref>
      <ref url="http://www.ubuntu.com/usn/usn-582-2" source="UBUNTU">USN-582-2</ref>
      <ref url="http://www.ubuntu.com/usn/usn-582-1" source="UBUNTU">USN-582-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-576-1" source="UBUNTU">USN-576-1</ref>
      <ref url="http://www.securitytracker.com/id?1019329" source="SECTRACK">1019329</ref>
      <ref url="http://www.securityfocus.com/bid/27406" source="BID">27406</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488971/100/0/threaded" source="BUGTRAQ">20080229 rPSA-2008-0093-1 thunderbird</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488002/100/0/threaded" source="BUGTRAQ">20080212 FLEA-2008-0001-1 firefox</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487826/100/0/threaded" source="BUGTRAQ">20080209 rPSA-2008-0051-1 firefox</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0105.html" source="REDHAT">RHSA-2008:0105</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0104.html" source="REDHAT">RHSA-2008:0104</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0103.html" source="REDHAT">RHSA-2008:0103</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:062" source="MANDRIVA">MDVSA-2008:062</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:048" source="MANDRIVA">MDVSA-2008:048</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1506" source="DEBIAN">DSA-1506</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1489" source="DEBIAN">DSA-1489</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1485" source="DEBIAN">DSA-1485</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1484" source="DEBIAN">DSA-1484</ref>
      <ref url="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093" source="CONFIRM">http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2008-0093" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2008-0093</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2008-0051" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2008-0051</ref>
      <ref url="http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html" source="CONFIRM">http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2008&amp;m=slackware-security.445399" source="SLACKWARE">SSA:2008-061-01</ref>
      <ref url="http://secunia.com/advisories/30327" source="SECUNIA">30327</ref>
      <ref url="http://secunia.com/advisories/29567" source="SECUNIA">29567</ref>
      <ref url="http://secunia.com/advisories/29211" source="SECUNIA">29211</ref>
      <ref url="http://secunia.com/advisories/29167" source="SECUNIA">29167</ref>
      <ref url="http://secunia.com/advisories/29164" source="SECUNIA">29164</ref>
      <ref url="http://secunia.com/advisories/29098" source="SECUNIA">29098</ref>
      <ref url="http://secunia.com/advisories/29086" source="SECUNIA">29086</ref>
      <ref url="http://secunia.com/advisories/29049" source="SECUNIA">29049</ref>
      <ref url="http://secunia.com/advisories/28958" source="SECUNIA">28958</ref>
      <ref url="http://secunia.com/advisories/28939" source="SECUNIA">28939</ref>
      <ref url="http://secunia.com/advisories/28924" source="SECUNIA">28924</ref>
      <ref url="http://secunia.com/advisories/28879" source="SECUNIA">28879</ref>
      <ref url="http://secunia.com/advisories/28877" source="SECUNIA">28877</ref>
      <ref url="http://secunia.com/advisories/28865" source="SECUNIA">28865</ref>
      <ref url="http://secunia.com/advisories/28864" source="SECUNIA">28864</ref>
      <ref url="http://secunia.com/advisories/28839" source="SECUNIA">28839</ref>
      <ref url="http://secunia.com/advisories/28818" source="SECUNIA">28818</ref>
      <ref url="http://secunia.com/advisories/28815" source="SECUNIA">28815</ref>
      <ref url="http://secunia.com/advisories/28808" source="SECUNIA">28808</ref>
      <ref url="http://secunia.com/advisories/28766" source="SECUNIA">28766</ref>
      <ref url="http://secunia.com/advisories/28754" source="SECUNIA">28754</ref>
      <ref url="http://secunia.com/advisories/28622/" source="SECUNIA">28622</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00006.html" source="SUSE">SUSE-SA:2008:008</ref>
      <ref url="http://browser.netscape.com/releasenotes/" source="CONFIRM">http://browser.netscape.com/releasenotes/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers prev="1" num="2.0.0.11"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.1.7"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers prev="1" num="2.0.0.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0419" published="2008-02-08" name="CVE-2008-0419" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8 allows remote attackers to steal navigation history and cause a denial of service (crash) via images in a page that uses designMode frames, which triggers memory corruption related to resize handles.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/879056" source="CERT-VN">VU#879056</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.html" source="FEDORA">FEDORA-2008-2118</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.html" source="FEDORA">FEDORA-2008-2060</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00381.html" source="FEDORA">FEDORA-2008-1535</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00309.html" source="FEDORA">FEDORA-2008-1459</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00274.html" source="FEDORA">FEDORA-2008-1435</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1995" source="CONFIRM">https://issues.rpath.com/browse/RPL-1995</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=400556" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=400556</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1793/references" source="VUPEN">ADV-2008-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0627/references" source="VUPEN">ADV-2008-0627</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0453/references" source="VUPEN">ADV-2008-0453</ref>
      <ref url="http://www.ubuntu.com/usn/usn-576-1" source="UBUNTU">USN-576-1</ref>
      <ref url="http://www.securitytracker.com/id?1019328" source="SECTRACK">1019328</ref>
      <ref url="http://www.securityfocus.com/bid/27683" source="BID">27683</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488971/100/0/threaded" source="BUGTRAQ">20080229 rPSA-2008-0093-1 thunderbird</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488002/100/0/threaded" source="BUGTRAQ">20080212 FLEA-2008-0001-1 firefox</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487826/100/0/threaded" source="BUGTRAQ">20080209 rPSA-2008-0051-1 firefox</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0105.html" source="REDHAT" adv="1">RHSA-2008:0105</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0104.html" source="REDHAT" adv="1">RHSA-2008:0104</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0103.html" source="REDHAT" adv="1">RHSA-2008:0103</ref>
      <ref url="http://www.mozilla.org/security/announce/2008/mfsa2008-06.html" source="CONFIRM">http://www.mozilla.org/security/announce/2008/mfsa2008-06.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:048" source="MANDRIVA">MDVSA-2008:048</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml" source="GENTOO">GLSA-200805-18</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1506" source="DEBIAN">DSA-1506</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1489" source="DEBIAN">DSA-1489</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1485" source="DEBIAN">DSA-1485</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1484" source="DEBIAN">DSA-1484</ref>
      <ref url="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093" source="CONFIRM">http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2008-0093" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2008-0093</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2008-0051" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2008-0051</ref>
      <ref url="http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html" source="CONFIRM">http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1" source="SUNALERT">238492</ref>
      <ref url="http://secunia.com/advisories/30620" source="SECUNIA">30620</ref>
      <ref url="http://secunia.com/advisories/30327" source="SECUNIA">30327</ref>
      <ref url="http://secunia.com/advisories/29567" source="SECUNIA" adv="1">29567</ref>
      <ref url="http://secunia.com/advisories/29167" source="SECUNIA" adv="1">29167</ref>
      <ref url="http://secunia.com/advisories/29164" source="SECUNIA" adv="1">29164</ref>
      <ref url="http://secunia.com/advisories/29086" source="SECUNIA" adv="1">29086</ref>
      <ref url="http://secunia.com/advisories/29049" source="SECUNIA" adv="1">29049</ref>
      <ref url="http://secunia.com/advisories/28958" source="SECUNIA" adv="1">28958</ref>
      <ref url="http://secunia.com/advisories/28939" source="SECUNIA" adv="1">28939</ref>
      <ref url="http://secunia.com/advisories/28924" source="SECUNIA" adv="1">28924</ref>
      <ref url="http://secunia.com/advisories/28879" source="SECUNIA" adv="1">28879</ref>
      <ref url="http://secunia.com/advisories/28877" source="SECUNIA" adv="1">28877</ref>
      <ref url="http://secunia.com/advisories/28865" source="SECUNIA" adv="1">28865</ref>
      <ref url="http://secunia.com/advisories/28864" source="SECUNIA" adv="1">28864</ref>
      <ref url="http://secunia.com/advisories/28839" source="SECUNIA" adv="1">28839</ref>
      <ref url="http://secunia.com/advisories/28818" source="SECUNIA" adv="1">28818</ref>
      <ref url="http://secunia.com/advisories/28815" source="SECUNIA" adv="1">28815</ref>
      <ref url="http://secunia.com/advisories/28808" source="SECUNIA" adv="1">28808</ref>
      <ref url="http://secunia.com/advisories/28766" source="SECUNIA" adv="1">28766</ref>
      <ref url="http://secunia.com/advisories/28758" source="SECUNIA" adv="1">28758</ref>
      <ref url="http://secunia.com/advisories/28754" source="SECUNIA" adv="1">28754</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11652" source="OVAL">oval:org.mitre.oval:def:11652</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00006.html" source="SUSE">SUSE-SA:2008:008</ref>
      <ref url="http://browser.netscape.com/releasenotes/" source="CONFIRM">http://browser.netscape.com/releasenotes/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers prev="1" num="2.0.0.11"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.1.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0420" published="2008-02-11" name="CVE-2008-0420" modified="2011-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">modules/libpr0n/decoders/bmp/nsBMPDecoder.cpp in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 does not properly perform certain calculations related to the mColors table, which allows remote attackers to read portions of memory uninitialized via a crafted 8-bit bitmap (BMP) file that triggers an out-of-bounds read within the heap, as demonstrated using a CANVAS element; or cause a denial of service (application crash) via a crafted 8-bit bitmap file that triggers an out-of-bounds read. NOTE: the initial public reports stated that this affected Firefox in Ubuntu 6.06 through 7.10.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.html" source="FEDORA">FEDORA-2008-2118</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.html" source="FEDORA">FEDORA-2008-2060</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=408076" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=408076</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40606" source="XF">firefox-bmp-dos(40606)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40491" source="XF">firefox-bmp-information-disclosure(40491)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1793/references" source="VUPEN" adv="1">ADV-2008-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0627/references" source="VUPEN" adv="1">ADV-2008-0627</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-576-1" source="UBUNTU">USN-576-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-582-2" source="UBUNTU">USN-582-2</ref>
      <ref url="http://www.ubuntu.com/usn/usn-582-1" source="UBUNTU">USN-582-1</ref>
      <ref url="http://www.securityfocus.com/bid/27826" source="BID">27826</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488264/100/0/threaded" source="BUGTRAQ">20080216 [HISPASEC] FireFox 2.0.0.11 and Opera 9.50 beta Remote Memory Information Leak, FireFox 2.0.0.11 Remote Denial of Service</ref>
      <ref url="http://www.mozilla.org/security/announce/2008/mfsa2008-07.html" source="CONFIRM">http://www.mozilla.org/security/announce/2008/mfsa2008-07.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:048" source="MANDRIVA">MDVSA-2008:048</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml" source="GENTOO">GLSA-200805-18</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1" source="SUNALERT">238492</ref>
      <ref url="http://securitytracker.com/id?1019434" source="SECTRACK">1019434</ref>
      <ref url="http://secunia.com/advisories/30620" source="SECUNIA" adv="1">30620</ref>
      <ref url="http://secunia.com/advisories/30327" source="SECUNIA" adv="1">30327</ref>
      <ref url="http://secunia.com/advisories/29167" source="SECUNIA" adv="1">29167</ref>
      <ref url="http://secunia.com/advisories/29098" source="SECUNIA" adv="1">29098</ref>
      <ref url="http://secunia.com/advisories/29049" source="SECUNIA" adv="1">29049</ref>
      <ref url="http://secunia.com/advisories/28839" source="SECUNIA" adv="1">28839</ref>
      <ref url="http://secunia.com/advisories/28758" source="SECUNIA" adv="1">28758</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10119" source="OVAL">oval:org.mitre.oval:def:10119</ref>
      <ref url="http://browser.netscape.com/releasenotes/" source="CONFIRM">http://browser.netscape.com/releasenotes/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.6.1"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.3"/>
        <vers num="1.0.5"/>
        <vers num="1.0.8"/>
        <vers num="1.5"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers prev="1" num="2.0.0.11"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.6"/>
        <vers prev="1" num="1.1.7"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.0.2"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.8"/>
        <vers num="1.5"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.13"/>
        <vers num="1.5.0.14"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0.0.0"/>
        <vers prev="1" num="2.0.0.11"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0421" published="2008-01-23" name="CVE-2008-0421" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Invision Gallery 2.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter in a rate command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod vendor="invision_power_services" name="invision_gallery">
        <vers prev="1" num="2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0422" published="2008-01-23" name="CVE-2008-0422" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in mail.php in boastMachine (aka bMachine) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0227" source="VUPEN">ADV-2008-0227</ref>
      <ref url="http://www.securityfocus.com/bid/32379" source="BID">32379</ref>
      <ref url="http://www.securityfocus.com/bid/27369" source="BID">27369</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/498521/100/0/threaded" source="BUGTRAQ">20081120 boastMachine v3.1 Remote Sql Injection</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39813" source="XF">boastmachine-mail-sql-injection(39813)</ref>
      <ref url="http://securityreason.com/securityalert/3563" source="SREASON">3563</ref>
    </refs>
    <vuln_soft>
      <prod vendor="boastmachine" name="boastmachine">
        <vers prev="1" num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0423" published="2008-01-23" name="CVE-2008-0423" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Lama Software allow remote attackers to execute arbitrary PHP code via a URL in the MY_CONF[classRoot] parameter to (1) inc.steps.access_error.php, (2) inc.steps.check_login.php, or (3) inc.steps.init_system.php in admin/functions/.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0230" source="VUPEN">ADV-2008-0230</ref>
      <ref url="http://www.securityfocus.com/bid/27380" source="BID">27380</ref>
      <ref url="http://secunia.com/advisories/28442" source="SECUNIA" adv="1">28442</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39821" source="XF">lamasoftware-myconf-file-include(39821)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lama" name="lama_software">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0424" published="2008-01-23" name="CVE-2008-0424" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in blog.php in Mooseguy Blog System (MGBS) 1.0 allows remote attackers to execute arbitrary SQL commands via the month parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0226" source="VUPEN">ADV-2008-0226</ref>
      <ref url="http://www.securityfocus.com/bid/27377" source="BID">27377</ref>
      <ref url="http://www.milw0rm.com/exploits/4951" source="MILW0RM">4951</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39816" source="XF">mooseguy-blog-sql-injection(39816)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mooseguy_blog_system" name="mgbs">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0425" published="2008-01-23" name="CVE-2008-0425" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Absolute path traversal vulnerability in explorerdir.php in Frimousse 0.0.2 allows remote attackers to read arbitrary files and list arbitrary directories via a full pathname in the name parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39797" source="XF">frimousse-explorerdir-directory-traversal(39797)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0216" source="VUPEN">ADV-2008-0216</ref>
      <ref url="http://www.securityfocus.com/bid/27385" source="BID">27385</ref>
      <ref url="http://www.milw0rm.com/exploits/4943" source="MILW0RM">4943</ref>
    </refs>
    <vuln_soft>
      <prod vendor="frimousse" name="frimousse">
        <vers num="0.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0426" published="2008-01-23" name="CVE-2008-0426" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in submit.php in PacerCMS before 0.6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) headline, or (3) text field in a message.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27386" source="BID" patch="1">27386</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39832" source="XF">pacercms-submit-xss(39832)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486796/100/0/threaded" source="BUGTRAQ">20080122 PacerCMS Multiple Vulnerabilities (XSS/SQL)</ref>
      <ref url="http://secunia.com/advisories/28605" source="SECUNIA" adv="1">28605</ref>
      <ref url="http://pacercms.sourceforge.net/index.php/2008/01/21/pacercms-061-streamlines-code-base-addresses-security-issue/" source="CONFIRM">http://pacercms.sourceforge.net/index.php/2008/01/21/pacercms-061-streamlines-code-base-addresses-security-issue/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pacercms" name="pacercms">
        <vers prev="1" num="0.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0427" published="2008-01-23" name="CVE-2008-0427" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in file.php in bloofoxCMS 0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39795" source="XF">bloofoxcms-file-directory-traversal(39795)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0218" source="VUPEN">ADV-2008-0218</ref>
      <ref url="http://www.securityfocus.com/bid/27361" source="BID">27361</ref>
      <ref url="http://secunia.com/advisories/28415" source="SECUNIA" adv="1">28415</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120093005310107&amp;w=2" source="BUGTRAQ">20080120 Bloofox CMS SQL Injection (Authentication bypass) , Source code</ref>
      <ref url="http://bugreport.ir/?/27" source="MISC">http://bugreport.ir/?/27</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486714/100/0/threaded" source="BUGTRAQ">20080120 Bloofox CMS SQL Injection (Authentication bypass) , Source codedisclosure</ref>
      <ref url="http://www.milw0rm.com/exploits/4945" source="MILW0RM">4945</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bloo" name="bloofoxcms">
        <vers num="0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0428" published="2008-01-23" name="CVE-2008-0428" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the login function in system/class_permissions.php in bloofoxCMS 0.3 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to admin/index.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39794" source="XF">bloofoxcms-index-sql-injection(39794)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0218" source="VUPEN">ADV-2008-0218</ref>
      <ref url="http://www.securityfocus.com/bid/27361" source="BID">27361</ref>
      <ref url="http://secunia.com/advisories/28415" source="SECUNIA" adv="1">28415</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120093005310107&amp;w=2" source="BUGTRAQ">20080120 Bloofox CMS SQL Injection (Authentication bypass) , Source code</ref>
      <ref url="http://bugreport.ir/?/27" source="MISC">http://bugreport.ir/?/27</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486714/100/0/threaded" source="BUGTRAQ">20080120 Bloofox CMS SQL Injection (Authentication bypass) , Source codedisclosure</ref>
      <ref url="http://www.milw0rm.com/exploits/4945" source="MILW0RM">4945</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bloofoxcms" name="bloofoxcms">
        <vers num="0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0429" published="2008-01-23" name="CVE-2008-0429" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange 2.0 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a forum_catview action.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0231" source="VUPEN">ADV-2008-0231</ref>
      <ref url="http://www.securityfocus.com/bid/27381" source="BID">27381</ref>
      <ref url="http://www.milw0rm.com/exploits/6401" source="MILW0RM">6401</ref>
      <ref url="http://www.milw0rm.com/exploits/4956" source="MILW0RM">4956</ref>
      <ref url="http://secunia.com/advisories/28581" source="SECUNIA" adv="1">28581</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39820" source="XF">alstrasoft-indexphp-sql-injection(39820)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alstrasoft" name="forum_pay_per_post_exchange">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0430" published="2008-01-23" name="CVE-2008-0430" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in form.php in 360 Web Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the IDFM parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39796" source="XF">360web-form-sql-injection(39796)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0217" source="VUPEN">ADV-2008-0217</ref>
      <ref url="http://www.securityfocus.com/bid/27364" source="BID">27364</ref>
      <ref url="http://www.milw0rm.com/exploits/4944" source="MILW0RM">4944</ref>
    </refs>
    <vuln_soft>
      <prod vendor="360_web_manager" name="360_web_manager">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0431" published="2008-01-23" name="CVE-2008-0431" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in administrator/download.php in IDMOS (aka Phoenix) 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0229" source="VUPEN">ADV-2008-0229</ref>
      <ref url="http://www.securityfocus.com/bid/27379" source="BID">27379</ref>
      <ref url="http://www.milw0rm.com/exploits/4954" source="MILW0RM">4954</ref>
      <ref url="http://secunia.com/advisories/28436" source="SECUNIA" adv="1">28436</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39823" source="XF">idmos-download-directory-traversal(39823)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="idmos" name="idmos_cms">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0432" published="2008-01-23" name="CVE-2008-0432" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in phpAutoVideo 2.21 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39771" source="XF">phpautovideo-index-xss(39771)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0225" source="VUPEN">ADV-2008-0225</ref>
      <ref url="http://www.securityfocus.com/bid/27346" source="BID">27346</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486591/100/0/threaded" source="BUGTRAQ">20080118 Agares PhpAutoVideo 2.21(XSS/RFI) Multiple Remote Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/28580" source="SECUNIA" adv="1">28580</ref>
      <ref url="http://securityreason.com/securityalert/3567" source="SREASON">3567</ref>
    </refs>
    <vuln_soft>
      <prod vendor="agares_media" name="phpautovideo">
        <vers prev="1" num="2.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0433" published="2008-01-23" name="CVE-2008-0433" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in theme/phpAutoVideo/LightTwoOh/sidebar.php in Agares phpAutoVideo 2.21 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the loadpage parameter, a different vector than CVE-2007-6614.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39770" source="XF">phpautovideo-sidebar-file-include(39770)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0225" source="VUPEN">ADV-2008-0225</ref>
      <ref url="http://www.securityfocus.com/bid/27346" source="BID">27346</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486591/100/0/threaded" source="BUGTRAQ">20080118 Agares PhpAutoVideo 2.21(XSS/RFI) Multiple Remote Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/28580" source="SECUNIA" adv="1">28580</ref>
      <ref url="http://securityreason.com/securityalert/3567" source="SREASON">3567</ref>
    </refs>
    <vuln_soft>
      <prod vendor="agares_media" name="phpautovideo">
        <vers prev="1" num="2.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0434" published="2008-01-23" name="CVE-2008-0434" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Format string vulnerability in the AXIMilter module in AXIGEN Mail Server 5.0.2 allows remote attackers to execute arbitrary code via format string specifiers in the CNHO command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39803" source="XF">axigen-aximilter-format-string(39803)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0237" source="VUPEN">ADV-2008-0237</ref>
      <ref url="http://www.securityfocus.com/bid/27363" source="BID">27363</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486722/100/0/threaded" source="BUGTRAQ">20080120 AXIGEN 5.0.x AXIMilter Format String Exploit</ref>
      <ref url="http://www.milw0rm.com/exploits/4947" source="MILW0RM">4947</ref>
      <ref url="http://secunia.com/advisories/28562" source="SECUNIA" adv="1">28562</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059788.html" source="FULLDISC">20080120 AXIGEN 5.0.x AXIMilter Format String Exploit</ref>
      <ref url="http://securityreason.com/securityalert/3570" source="SREASON">3570</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gecad_technologies" name="axigen_mail_server">
        <vers num="5.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0435" published="2008-01-23" name="CVE-2008-0435" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in OZJournals 2.1.1 allows remote attackers to read portions of arbitrary files via a .. (dot dot) in the id parameter in a printpreview action.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0228" source="VUPEN">ADV-2008-0228</ref>
      <ref url="http://www.securityfocus.com/bid/27375" source="BID">27375</ref>
      <ref url="http://www.milw0rm.com/exploits/4953" source="MILW0RM">4953</ref>
      <ref url="http://secunia.com/advisories/28582" source="SECUNIA" adv="1">28582</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39815" source="XF">ozjournals-id-directory-traversal(39815)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ozjournals" name="ozjournals">
        <vers num="2.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0436" published="2008-01-23" name="CVE-2008-0436" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in profile-upload/upload.asp in PD9 Software MegaBBS 1.5.14b allows remote attackers to inject arbitrary web script or HTML via the target parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27368" source="BID">27368</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486723/100/0/threaded" source="BUGTRAQ">20080120 MegaBBS ASP Forum Cross-Site Scripting</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39812" source="XF">megabbs-upload-xss(39812)</ref>
      <ref url="http://securityreason.com/securityalert/3565" source="SREASON">3565</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pd9_software" name="megabbs">
        <vers num="1.5.14b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0437" published="2008-01-23" name="CVE-2008-0437" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in the WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100, as used in the installation process for HP Virtual Rooms, allow remote attackers to execute arbitrary code via a long (1) AuthenticationURL, (2) PortalAPIURL, or (3) cabroot property value.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0236" source="VUPEN">ADV-2008-0236</ref>
      <ref url="http://www.securityfocus.com/bid/27384" source="BID">27384</ref>
      <ref url="http://secunia.com/advisories/28595" source="SECUNIA" adv="1">28595</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=120098751528333&amp;w=2" source="FULLDISC">20080122 HP Virtual Rooms WebHPVCInstall Control Multiple Buffer Overflows</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39836" source="XF">hpvirtualrooms-hpvirtualrooms14-activex-bo(39836)</ref>
      <ref url="http://www.milw0rm.com/exploits/4959" source="MILW0RM">4959</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="virtual_rooms">
        <vers num="1.0.0.100"/>
      </prod>
      <prod vendor="microsoft" name="activex">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0438" published="2008-01-23" name="CVE-2008-0438" modified="2012-10-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the font rendering functionality in Novemberborn sIFR 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the txt parameter to a Flash (SWF) file, as demonstrated by fonts/FuturaLt.swf.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27394" source="BID" patch="1">27394</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487585/100/200/threaded" source="BUGTRAQ">20080205 Re: PR07-38: XSS on sIFR</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486787/100/0/threaded" source="BUGTRAQ">20080122 PR07-38: XSS on sIFR</ref>
      <ref url="http://www.procheckup.com/Vulnerability_PR07-38.php" source="MISC">http://www.procheckup.com/Vulnerability_PR07-38.php</ref>
      <ref url="http://osvdb.org/41006" source="OSVDB">41006</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39835" source="XF">sifr-fontname-xss(39835)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486829/100/0/threaded" source="BUGTRAQ">20080122 Re: PR07-38: XSS on sIFR</ref>
      <ref url="http://securityreason.com/securityalert/3571" source="SREASON">3571</ref>
      <ref url="http://novemberborn.net/sifr/2.0.3" source="CONFIRM">http://novemberborn.net/sifr/2.0.3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novemberborn" name="sifr">
        <vers num="2.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0439" published="2008-01-23" name="CVE-2008-0439" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in templates/default/admincp/attachments_header.php in DeluxeBB 1.1 allows remote attackers to inject arbitrary web script or HTML via the lang_listofmatches parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486804/100/0/threaded" source="BUGTRAQ">20080122 DeluxeBB 1.1 XSS Vulnerabilitie</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39829" source="XF">deluxbb-attachmentsheader-xss(39829)</ref>
      <ref url="http://www.securityfocus.com/bid/27401" source="BID">27401</ref>
      <ref url="http://securityreason.com/securityalert/3564" source="SREASON">3564</ref>
    </refs>
    <vuln_soft>
      <prod vendor="deluxebb" name="deluxebb">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0440" published="2008-01-23" name="CVE-2008-0440" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">AlstraSoft Forum Pay Per Post Exchange 2.0 stores passwords in cleartext, which makes it easier for attackers to access user accounts.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/4956" source="MILW0RM">4956</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alstrasoft" name="forum_pay_per_post_exchange">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2008-0441" published="2008-01-24" name="CVE-2008-0441" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">IBM Tivoli Business Service Manager (TBSM) 4.1.1 stores passwords in cleartext (1) after external authentication, which triggers writing the password to SM_server.log; and (2) after a reconfig action; which allows local users to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39822" source="XF">tbsm-reconfig-information-disclosure(39822)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0240" source="VUPEN">ADV-2008-0240</ref>
      <ref url="http://www.securitytracker.com/id?1019250" source="SECTRACK">1019250</ref>
      <ref url="http://www.securityfocus.com/bid/27388" source="BID">27388</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg24017939" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg24017939</ref>
      <ref url="http://secunia.com/advisories/28603" source="SECUNIA" adv="1">28603</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_business_service_manager">
        <vers num="4.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0442" published="2008-01-24" name="CVE-2008-0442" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the ffile parameter, a different vector than CVE-2008-0376.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27383" source="BID">27383</ref>
      <ref url="http://secunia.com/advisories/28568" source="SECUNIA" adv="1">28568</ref>
    </refs>
    <vuln_soft>
      <prod vendor="small_axe_solutions" name="weblog">
        <vers num="0.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0443" published="2008-01-24" name="CVE-2008-0443" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the FileUploader.FUploadCtl.1 ActiveX control in FileUploader.dll 2.0.0.2 in Lycos FileUploader Module allows remote attackers to execute arbitrary code via a long HandwriterFilename property value.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0253" source="VUPEN">ADV-2008-0253</ref>
      <ref url="http://www.securityfocus.com/bid/27411" source="BID">27411</ref>
      <ref url="http://www.milw0rm.com/exploits/4967" source="MILW0RM">4967</ref>
      <ref url="http://secunia.com/advisories/28599" source="SECUNIA" adv="1">28599</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39849" source="XF">lycosfileuploader-fileuploader-activex-bo(39849)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lycos" name="fileuploader.dll">
        <vers num="2.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0444" published="2008-01-24" name="CVE-2008-0444" modified="2009-08-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) before 2.7.0 allows remote attackers to inject arbitrary web script or HTML via subtext parameter to unspecified components.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27399" source="BID" patch="1">27399</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39828" source="XF">elog-subtext-xss(39828)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0265" source="VUPEN">ADV-2008-0265</ref>
      <ref url="http://secunia.com/advisories/28589" source="SECUNIA" adv="1">28589</ref>
      <ref url="http://osvdb.org/41681" source="OSVDB">41681</ref>
      <ref url="http://midas.psi.ch/elog/download/ChangeLog" source="CONFIRM">http://midas.psi.ch/elog/download/ChangeLog</ref>
    </refs>
    <vuln_soft>
      <prod vendor="elog" name="elog">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.5"/>
        <vers num="1.3.6"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.3.4"/>
        <vers num="2.3.5"/>
        <vers num="2.3.6"/>
        <vers num="2.3.7"/>
        <vers num="2.3.8"/>
        <vers num="2.3.9"/>
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.5.4"/>
        <vers num="2.5.5"/>
        <vers num="2.5.6"/>
        <vers num="2.5.7"/>
        <vers num="2.5.8"/>
        <vers num="2.5.9"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0445" published="2008-01-24" name="CVE-2008-0445" modified="2009-08-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The replace_inline_img function in elogd in Electronic Logbook (ELOG) before 2.7.1 allows remote attackers to cause a denial of service (infinite loop) via crafted logbook entries.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27399" source="BID" patch="1">27399</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39824" source="XF">elog-elogd-logbook-dos(39824)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0265" source="VUPEN">ADV-2008-0265</ref>
      <ref url="http://secunia.com/advisories/28589" source="SECUNIA" adv="1">28589</ref>
    </refs>
    <vuln_soft>
      <prod vendor="elog" name="elog">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.5"/>
        <vers num="1.3.6"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.3.4"/>
        <vers num="2.3.5"/>
        <vers num="2.3.6"/>
        <vers num="2.3.7"/>
        <vers num="2.3.8"/>
        <vers num="2.3.9"/>
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.5.4"/>
        <vers num="2.5.5"/>
        <vers num="2.5.6"/>
        <vers num="2.5.7"/>
        <vers num="2.5.8"/>
        <vers num="2.5.9"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0446" published="2008-01-24" name="CVE-2008-0446" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in voircom.php in LulieBlog 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/4969" source="MILW0RM">4969</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39854" source="XF">lulieblog-voircom-sql-injection(39854)</ref>
      <ref url="http://www.securityfocus.com/bid/27416" source="BID">27416</ref>
    </refs>
    <vuln_soft>
      <prod vendor="julian_pawlowski" name="lulieblog">
        <vers num="1.02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0447" published="2008-01-24" name="CVE-2008-0447" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Foojan WMS PHP Weblog 1.0 allows remote attackers to execute arbitrary SQL commands via the story parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/4968" source="MILW0RM">4968</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39855" source="XF">foojanwms-index-sql-injection(39855)</ref>
      <ref url="http://www.securityfocus.com/bid/27415" source="BID">27415</ref>
    </refs>
    <vuln_soft>
      <prod vendor="foojan" name="php_weblog">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0448" published="2008-01-24" name="CVE-2008-0448" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in utils/class_HTTPRetriever.php in phpSearch allows remote attackers to execute arbitrary PHP code via a URL in the libcurlemuinc parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39805" source="XF">phpsearch-classhttpretriever-file-include(39805)</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120093067011293&amp;w=2" source="BUGTRAQ">20080120 Php Search Remote Inclusion</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cybergl_dev_team" name="phpsearch">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0449" published="2008-01-24" name="CVE-2008-0449" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in paypalresult.asp in VP-ASP Shopping Cart 6.50 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27347" source="BID" patch="1">27347</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39811" source="XF">vpasp-paypalresult-sql-injection(39811)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rocksalt_international" name="vp_asp">
        <vers num="4.00"/>
        <vers num="4.50"/>
        <vers num="5.00"/>
        <vers num="5.50"/>
        <vers num="6.00"/>
        <vers num="6.50"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0450" published="2008-01-24" name="CVE-2008-0450" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in BLOG:CMS 4.2.1.c allow remote attackers to execute arbitrary PHP code via a URL in the (1) DIR_PLUGINS parameter to (a) index.php, and the (2) DIR_LIBS parameter to (b) media.php and (c) xmlrpc/server.php in admin/.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486743/100/0/threaded" source="BUGTRAQ">20080121 BLOG:CMS 4.2.1.c (DIR_PLUGINS) Multiple Remote File Include</ref>
      <ref url="http://securityreason.com/securityalert/3576" source="SREASON">3576</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blog_cms" name="blog_cms">
        <vers num="4.2.1_c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0451" published="2008-01-24" name="CVE-2008-0451" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in PacerCMS 0.6 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) siteadmin/article-edit.php; and unspecified parameters to (2) submitted-edit.php, (3) page-edit.php, (4) section-edit.php, (5) staff-edit.php, and (6) staff-access.php in siteadmin/.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27397" source="BID" patch="1">27397</ref>
      <ref url="http://pacercms.sourceforge.net/index.php/2008/01/21/pacercms-061-streamlines-code-base-addresses-security-issue/" source="MISC" patch="1">http://pacercms.sourceforge.net/index.php/2008/01/21/pacercms-061-streamlines-code-base-addresses-security-issue/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39833" source="XF">pacercms-articleedit-sql-injection(39833)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486796/100/0/threaded" source="BUGTRAQ">20080122 PacerCMS Multiple Vulnerabilities (XSS/SQL)</ref>
      <ref url="http://securityreason.com/securityalert/3574" source="SREASON">3574</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pacercms" name="pacercms">
        <vers num="0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0452" published="2008-01-24" name="CVE-2008-0452" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in articles.php in Siteman 1.1.9 allows remote attackers to read arbitrary files via directory traversal sequences in the cat parameter in a viewart action.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/4973" source="MILW0RM">4973</ref>
      <ref url="http://www.securityfocus.com/bid/27422" source="BID">27422</ref>
    </refs>
    <vuln_soft>
      <prod vendor="siteman" name="siteman">
        <vers num="1.1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0453" published="2008-01-24" name="CVE-2008-0453" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in list.php in Easysitenetwork Recipe allows remote attackers to execute arbitrary SQL commands via the categoryid parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39853" source="XF">easysitenetworkrecipe-list-sql-injection(39853)</ref>
      <ref url="http://www.securityfocus.com/bid/27405" source="BID">27405</ref>
      <ref url="http://www.milw0rm.com/exploits/4960" source="MILW0RM">4960</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easysitenetwork" name="recipe_website_script">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0454" published="2008-01-24" name="CVE-2008-0454" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Title field of a (1) Dailymotion and possibly (2) Metacafe movie in the Skype video gallery, accessible through a search within the "Add video to chat" dialog, aka "videomood XSS."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/248184" source="CERT-VN">VU#248184</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39754" source="XF">skype-addvideotochat-code-execution(39754)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0194" source="VUPEN">ADV-2008-0194</ref>
      <ref url="http://www.securityfocus.com/bid/27338" source="BID">27338</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486512/100/0/threaded" source="BUGTRAQ">20080117 RE: Skype videomood XSS</ref>
      <ref url="http://www.gnucitizen.org/blog/vulnerabilities-in-skype" source="MISC">http://www.gnucitizen.org/blog/vulnerabilities-in-skype</ref>
      <ref url="http://www.critical.lt/?opinions/show/1470" source="MISC">http://www.critical.lt/?opinions/show/1470</ref>
      <ref url="http://skype.com/security/skype-sb-2008-001.html" source="CONFIRM">http://skype.com/security/skype-sb-2008-001.html</ref>
      <ref url="http://skype.com/security/skype-sb-2008-001-update1.html" source="CONFIRM">http://skype.com/security/skype-sb-2008-001-update1.html</ref>
      <ref url="http://share.skype.com/sites/security/2008/01/skype_cross_zone_scripting_vul.html" source="CONFIRM">http://share.skype.com/sites/security/2008/01/skype_cross_zone_scripting_vul.html</ref>
      <ref url="http://aviv.raffon.net/2008/01/17/SkypeCrosszoneScriptingVulnerability.aspx" source="MISC">http://aviv.raffon.net/2008/01/17/SkypeCrosszoneScriptingVulnerability.aspx</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2008-01/0363.html" source="FULLDISC">20080117 Re: Skype videomood XSS</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2008-01/0337.html" source="FULLDISC">20080117 Skype videomood XSS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num=""/>
      </prod>
      <prod vendor="skype_technologies" name="skype">
        <vers num="3.5"/>
        <vers num="3.6"/>
        <vers prev="1" num="3.6.0.244"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0455" published="2008-01-24" name="CVE-2008-0455" modified="2013-02-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27409" source="BID">27409</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486847/100/0/threaded" source="BUGTRAQ">20080122 Apache mod_negotiation Xss and Http Response Splitting</ref>
      <ref url="http://www.mindedsecurity.com/MSA01150108.html" source="MISC">http://www.mindedsecurity.com/MSA01150108.html</ref>
      <ref url="http://securitytracker.com/id?1019256" source="SECTRACK">1019256</ref>
      <ref url="http://secunia.com/advisories/51607" source="SECUNIA">51607</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0130.html" source="REDHAT">RHSA-2013:0130</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-1594.html" source="REDHAT">RHSA-2012:1594</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-1592.html" source="REDHAT">RHSA-2012:1592</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-1591.html" source="REDHAT">RHSA-2012:1591</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39867" source="XF">apache-modnegotiation-xss(39867)</ref>
      <ref url="http://securityreason.com/securityalert/3575" source="SREASON">3575</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200803-19.xml" source="GENTOO">GLSA-200803-19</ref>
      <ref url="http://secunia.com/advisories/29348" source="SECUNIA">29348</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.3.11"/>
        <vers num="1.3.12"/>
        <vers num="1.3.14"/>
        <vers num="1.3.17"/>
        <vers num="1.3.18"/>
        <vers num="1.3.19"/>
        <vers num="1.3.20"/>
        <vers num="1.3.22"/>
        <vers num="1.3.23"/>
        <vers num="1.3.24"/>
        <vers num="1.3.25"/>
        <vers num="1.3.26"/>
        <vers num="1.3.27"/>
        <vers num="1.3.28"/>
        <vers num="1.3.29"/>
        <vers num="1.3.3"/>
        <vers num="1.3.31"/>
        <vers num="1.3.32"/>
        <vers num="1.3.33"/>
        <vers num="1.3.34"/>
        <vers num="1.3.35"/>
        <vers num="1.3.36"/>
        <vers num="1.3.37"/>
        <vers num="1.3.39"/>
        <vers num="2.0"/>
        <vers num="2.0.28" edition="beta"/>
        <vers num="2.0.32"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.40"/>
        <vers num="2.0.41"/>
        <vers num="2.0.42"/>
        <vers num="2.0.43"/>
        <vers num="2.0.44"/>
        <vers num="2.0.45"/>
        <vers num="2.0.46"/>
        <vers num="2.0.47"/>
        <vers num="2.0.48"/>
        <vers num="2.0.49"/>
        <vers num="2.0.50"/>
        <vers num="2.0.51"/>
        <vers num="2.0.52"/>
        <vers num="2.0.53"/>
        <vers num="2.0.54"/>
        <vers num="2.0.55"/>
        <vers num="2.0.56"/>
        <vers num="2.0.58"/>
        <vers num="2.0.59"/>
        <vers num="2.0.60"/>
        <vers num="2.0.61"/>
        <vers num="2.0.9"/>
        <vers num="2.2.0"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2008-0456" published="2008-01-24" name="CVE-2008-0456" modified="2013-02-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39893" source="XF">apache-modnegotiation-response-splitting(39893)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securityfocus.com/bid/27409" source="BID">27409</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486847/100/0/threaded" source="BUGTRAQ">20080122 Apache mod_negotiation Xss and Http Response Splitting</ref>
      <ref url="http://www.mindedsecurity.com/MSA01150108.html" source="MISC">http://www.mindedsecurity.com/MSA01150108.html</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://securitytracker.com/id?1019256" source="SECTRACK">1019256</ref>
      <ref url="http://securityreason.com/securityalert/3575" source="SREASON">3575</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200803-19.xml" source="GENTOO">GLSA-200803-19</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://secunia.com/advisories/29348" source="SECUNIA">29348</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0130.html" source="REDHAT">RHSA-2013:0130</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers prev="1" num="1.3.39"/>
        <vers prev="1" num="2.0.61"/>
        <vers prev="1" num="2.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0457" published="2008-02-07" name="CVE-2008-0457" modified="2011-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exec System Recovery Manager 7.0 and 7.0.1, allows remote attackers to upload and execute arbitrary JSP files via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.symantec.com/avcenter/security/Content/2008.02.04.html" source="CONFIRM" patch="1">http://www.symantec.com/avcenter/security/Content/2008.02.04.html</ref>
      <ref url="http://seer.entsupport.symantec.com/docs/297171.htm" source="CONFIRM" patch="1">http://seer.entsupport.symantec.com/docs/297171.htm</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-08-003.html" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-08-003.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0413" source="VUPEN" adv="1">ADV-2008-0413</ref>
      <ref url="http://www.securitytracker.com/id?1019303" source="SECTRACK">1019303</ref>
      <ref url="http://www.securityfocus.com/bid/27487" source="BID">27487</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487688/100/0/threaded" source="BUGTRAQ">20080206 ZDI-08-003: Symantec Backup Exec Remote File Upload Vulnerability</ref>
      <ref url="http://www.milw0rm.com/exploits/5078" source="MILW0RM">5078</ref>
      <ref url="http://secunia.com/advisories/28787" source="SECUNIA" adv="1">28787</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="backupexec_system_recovery">
        <vers num="7.0"/>
        <vers num="7.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0458" published="2008-01-25" name="CVE-2008-0458" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in function/sources.php in SLAED CMS 2.5 Lite allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the newlang parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0308" source="VUPEN">ADV-2008-0308</ref>
      <ref url="http://www.securityfocus.com/bid/27426" source="BID">27426</ref>
      <ref url="http://www.milw0rm.com/exploits/4975" source="MILW0RM">4975</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39897" source="XF">slaedcms-index-file-include(39897)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="slaed" name="slaed_cms">
        <vers num="2.5_lite"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0459" published="2008-01-25" name="CVE-2008-0459" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in update/index.php in Liquid-Silver CMS 0.35, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the update parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0309" source="VUPEN">ADV-2008-0309</ref>
      <ref url="http://www.securityfocus.com/bid/27425" source="BID">27425</ref>
      <ref url="http://www.milw0rm.com/exploits/4976" source="MILW0RM">4976</ref>
      <ref url="http://secunia.com/advisories/28619" source="SECUNIA" adv="1">28619</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39895" source="XF">liquidsilvercms-index-file-include(39895)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="liquidsilvercms" name="liquidsilvercms">
        <vers num="0.3"/>
        <vers num="0.35"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0460" published="2008-01-25" name="CVE-2008-0460" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in api.php in (1) MediaWiki 1.11 through 1.11.0rc1, 1.10 through 1.10.2, 1.9 through 1.9.4, and 1.8; and (2) the BotQuery extension for MediaWiki 1.7 and earlier; when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0280" source="VUPEN">ADV-2008-0280</ref>
      <ref url="http://secunia.com/advisories/28629" source="SECUNIA" adv="1">28629</ref>
      <ref url="http://lists.wikimedia.org/pipermail/mediawiki-announce/2008-January/000068.html" source="MLIST">[MediaWiki-announce] 20080124 MediaWiki 1.11.1, 1.10.3, 1.9.5 released</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00189.html" source="FEDORA">FEDORA-2008-2288</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00147.html" source="FEDORA">FEDORA-2008-2245</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39901" source="XF">mediawiki-api-xss(39901)</ref>
      <ref url="http://www.securityfocus.com/bid/28137" source="BID">28137</ref>
      <ref url="http://secunia.com/advisories/29266" source="SECUNIA">29266</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.10.0"/>
        <vers num="1.10.1"/>
        <vers num="1.10.2"/>
        <vers num="1.11"/>
        <vers num="1.11.0rc1"/>
        <vers num="1.7.0"/>
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.9.0"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers num="1.9.3"/>
        <vers num="1.9.4"/>
      </prod>
      <prod vendor="mediawiki" name="mediawiki_botquery_ext">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="ie">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0461" published="2008-01-25" name="CVE-2008-0461" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in the Search module in PHP-Nuke 8.0 FINAL and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the sid parameter in a comments action to modules.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0264" source="VUPEN">ADV-2008-0264</ref>
      <ref url="http://www.securityfocus.com/bid/27408" source="BID">27408</ref>
      <ref url="http://www.milw0rm.com/exploits/4965" source="MILW0RM">4965</ref>
      <ref url="http://secunia.com/advisories/28624" source="SECUNIA" adv="1">28624</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39850" source="XF">phpnuke-index-search-sql-injection(39850)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers prev="1" num="8.0_final"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0462" published="2008-01-25" name="CVE-2008-0462" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Archive 5.x before 5.x-1.8 module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://drupal.org/node/213478" source="CONFIRM" patch="1">http://drupal.org/node/213478</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0278" source="VUPEN">ADV-2008-0278</ref>
      <ref url="http://www.securityfocus.com/bid/27436" source="BID">27436</ref>
      <ref url="http://secunia.com/advisories/28632" source="SECUNIA" adv="1">28632</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39898" source="XF">drupal-archive-unspecified-xss(39898)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="archive_module">
        <vers prev="1" num="5_1.7"/>
      </prod>
      <prod vendor="drupal" name="drupal">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0463" published="2008-01-25" name="CVE-2008-0463" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Workflow 4.7.x before 4.7.x-1.2 and 5.x before 5.x-1.2 module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving node properties.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://drupal.org/node/213473" source="CONFIRM" patch="1">http://drupal.org/node/213473</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0279" source="VUPEN">ADV-2008-0279</ref>
      <ref url="http://secunia.com/advisories/28633" source="SECUNIA" adv="1">28633</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39896" source="XF">workflow-messages-xss(39896)</ref>
      <ref url="http://www.securityfocus.com/bid/27444" source="BID">27444</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="workflow">
        <vers prev="1" num="4.7.x-1.1"/>
        <vers prev="1" num="5.x-1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0464" published="2008-01-25" name="CVE-2008-0464" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in archiv.cgi in absofort aconon Mail 2007 Enterprise SQL 11.7.0 and Mail 2004 Enterprise SQL 11.5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0310" source="VUPEN">ADV-2008-0310</ref>
      <ref url="http://www.securityfocus.com/bid/27427" source="BID">27427</ref>
      <ref url="http://www.milw0rm.com/exploits/4977" source="MILW0RM">4977</ref>
      <ref url="http://secunia.com/advisories/28617" source="SECUNIA" adv="1">28617</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059856.html" source="FULLDISC">20080124 Directory Traversal Vulnerability in Aconon Mail</ref>
      <ref url="http://burnachurch.com/67/directory-traversal-luecke-in-aconon-mail/" source="MISC">http://burnachurch.com/67/directory-traversal-luecke-in-aconon-mail/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="absofort" name="aconon_mail_enterprise_sql">
        <vers num="11.5.1" edition="2004"/>
        <vers num="11.7.0" edition="2007"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0465" published="2008-01-25" name="CVE-2008-0465" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in optimizer.php in Seagull 0.6.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the files parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">The vendor has released a patch for 0.6.3.  A patch can be found at the following location: 

http://seagullproject.org/download/

</sol>
    </sols>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39902" source="XF">seagullstable-optimizer-directory-traversal(39902)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0311" source="VUPEN">ADV-2008-0311</ref>
      <ref url="http://www.securityfocus.com/bid/27437" source="BID">27437</ref>
      <ref url="http://www.milw0rm.com/exploits/4980" source="MILW0RM">4980</ref>
      <ref url="http://secunia.com/advisories/28646" source="SECUNIA" adv="1">28646</ref>
      <ref url="http://seagullproject.org/publisher/articleview/action/view/frmArticleID/98/" source="CONFIRM">http://seagullproject.org/publisher/articleview/action/view/frmArticleID/98/</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2008-January/001891.html" source="VIM">20080129 Seagull 0.6.3 Remote File Disclosure Vulnerability fixed</ref>
    </refs>
    <vuln_soft>
      <prod vendor="seagullproject.org" name="seagull">
        <vers num="0.6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0466" published="2008-01-28" name="CVE-2008-0466" modified="2010-12-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02, does not require authentication, which allows remote attackers to list directories and read files.  NOTE: this can be leveraged for listings outside the configured directory tree by exploiting a separate directory traversal vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.webwizguide.com/webwizrichtexteditor/kb/release_notes.asp" source="MISC">http://www.webwizguide.com/webwizrichtexteditor/kb/release_notes.asp</ref>
      <ref url="http://www.securityfocus.com/bid/27419" source="BID">27419</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486868/100/0/threaded" source="BUGTRAQ">20080123 Web Wiz Rich Text Editor Directory traversal + HTM/HTML filecreation on the server</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486866/100/0/threaded" source="BUGTRAQ">20080123 Web Wiz Forums Directory traversal</ref>
      <ref url="http://www.milw0rm.com/exploits/4971" source="MILW0RM">4971</ref>
      <ref url="http://www.milw0rm.com/exploits/4970" source="MILW0RM">4970</ref>
      <ref url="http://www.bugreport.ir/?/31" source="MISC">http://www.bugreport.ir/?/31</ref>
      <ref url="http://www.bugreport.ir/?/29" source="MISC">http://www.bugreport.ir/?/29</ref>
      <ref url="http://securitytracker.com/id?1019267" source="SECTRACK">1019267</ref>
      <ref url="http://securityreason.com/securityalert/3584" source="SREASON">3584</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webwiz" name="web_wiz_forums">
        <vers num="9.07"/>
      </prod>
      <prod vendor="webwiz" name="web_wiz_newspad">
        <vers num="1.02"/>
      </prod>
      <prod vendor="webwiz" name="web_wiz_rich_text_editor">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0467" published="2008-01-28" name="CVE-2008-0467" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Firebird before 2.0.4, and 2.1.x before 2.1.0 RC1, might allow remote attackers to execute arbitrary code via a long username.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39981" source="XF">firebird-username-bo(39981)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0300" source="VUPEN">ADV-2008-0300</ref>
      <ref url="http://www.securitytracker.com/id?1019277" source="SECTRACK">1019277</ref>
      <ref url="http://www.securityfocus.com/bid/27467" source="BID">27467</ref>
      <ref url="http://tracker.firebirdsql.org/browse/CORE-1603" source="CONFIRM">http://tracker.firebirdsql.org/browse/CORE-1603</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=570816&amp;group_id=9028" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=570816&amp;group_id=9028</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=9028&amp;release_id=570800" source="CONFIRM">http://sourceforge.net/project/shownotes.php?group_id=9028&amp;release_id=570800</ref>
      <ref url="http://secunia.com/advisories/28596" source="SECUNIA" adv="1">28596</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1529" source="DEBIAN">DSA-1529</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200803-02.xml" source="GENTOO">GLSA-200803-02</ref>
      <ref url="http://secunia.com/advisories/29501" source="SECUNIA">29501</ref>
      <ref url="http://secunia.com/advisories/29203" source="SECUNIA">29203</ref>
    </refs>
    <vuln_soft>
      <prod vendor="firebirdsql" name="firebird">
        <vers prev="1" num="2.0.3"/>
        <vers prev="1" num="2.1" edition="rc1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0468" published="2008-01-29" name="CVE-2008-0468" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in category.php in Flinx 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0313" source="VUPEN">ADV-2008-0313</ref>
      <ref url="http://www.securityfocus.com/bid/27448" source="BID">27448</ref>
      <ref url="http://www.milw0rm.com/exploits/4985" source="MILW0RM">4985</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39930" source="XF">flinx-category-sql-injection(39930)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flinx" name="flinx">
        <vers prev="1" num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0469" published="2008-01-29" name="CVE-2008-0469" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Tiger Php News System (TPNS) 1.0b and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newscat action.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39908" source="XF">tigerphpnewssystem-catid-sql-injection(39908)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0312" source="VUPEN">ADV-2008-0312</ref>
      <ref url="http://www.securityfocus.com/bid/27445" source="BID">27445</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486961/100/0/threaded" source="BUGTRAQ">20080124 Tiger PHP News System SQL Injection</ref>
      <ref url="http://www.milw0rm.com/exploits/4984" source="MILW0RM">4984</ref>
      <ref url="http://secunia.com/advisories/28641" source="SECUNIA" adv="1">28641</ref>
      <ref url="http://securityreason.com/securityalert/3587" source="SREASON">3587</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tiger_php_news_system" name="tiger_php_news_system">
        <vers prev="1" num="1.0b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0470" published="2008-01-29" name="CVE-2008-0470" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">A certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteStr method.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39904" source="XF">comodo-antivirus-command-execution(39904)</ref>
      <ref url="http://www.securityfocus.com/bid/27424" source="BID">27424</ref>
      <ref url="http://www.milw0rm.com/exploits/4974" source="MILW0RM">4974</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comodo" name="comodo_antivirus">
        <vers num="2.0"/>
      </prod>
      <prod vendor="microsoft" name="activex">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0471" published="2008-01-29" name="CVE-2008-0471" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in privmsg.php in phpBB 2.0.22 allows remote attackers to delete private messages (PM) as arbitrary users via a deleteall action.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487004/100/0/threaded" source="BUGTRAQ">20080123 phpBB 2.0.22 Remote PM Delete XSRF Vulnerability</ref>
      <ref url="http://secunia.com/advisories/28630" source="SECUNIA" adv="1">28630</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1488" source="DEBIAN">DSA-1488</ref>
      <ref url="http://securityreason.com/securityalert/3585" source="SREASON">3585</ref>
      <ref url="http://secunia.com/advisories/28871" source="SECUNIA">28871</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=463589" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=463589</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb" name="phpbb">
        <vers num="2.0.22"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0472" published="2008-01-29" name="CVE-2008-0472" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in modcp.php in Woltlab Burning Board (wBB) 2.3.6 PL2 allows remote attackers to delete threads as moderators or administrators via a thread_del action.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39878" source="XF">wbb-modcp-csrf(39878)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486884/100/0/threaded" source="BUGTRAQ">20080123 Woltlab Burning Board 2.3.6 PL2 Remote Delete Thread XSRF Vulnerability</ref>
      <ref url="http://secunia.com/advisories/28634" source="SECUNIA" adv="1">28634</ref>
      <ref url="http://securityreason.com/securityalert/3586" source="SREASON">3586</ref>
    </refs>
    <vuln_soft>
      <prod vendor="woltlab" name="burning_board">
        <vers num="2.3.6_pl2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0473" published="2008-01-29" name="CVE-2008-0473" modified="2009-09-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">RTE_popup_save_file.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to upload (1) .html and (2) .htm files via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1019267" source="SECTRACK">1019267</ref>
      <ref url="http://www.securityfocus.com/bid/27420" source="BID">27420</ref>
      <ref url="http://www.securityfocus.com/bid/27419" source="BID">27419</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486868/100/0/threaded" source="BUGTRAQ">20080123 Web Wiz Rich Text Editor Directory traversal + HTM/HTML filecreation on the server</ref>
      <ref url="http://www.milw0rm.com/exploits/4971" source="MILW0RM">4971</ref>
      <ref url="http://www.bugreport.ir/?/31" source="MISC">http://www.bugreport.ir/?/31</ref>
      <ref url="http://securityreason.com/securityalert/3584" source="SREASON">3584</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web_wiz" name="rich_text_editor">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0474" published="2008-01-29" name="CVE-2008-0474" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 8.1 build 8100 allow remote attackers to inject arbitrary web script or HTML via the (1) showlink parameter to jsp/DiscoveryProfiles.jsp; the (2) attributeIDs, (3) attributeToSelect, (4) redirectto, and (5) resourceid parameters to (a) jsp/ThresholdActionConfiguration.jsp; the (6) page and (7) redirect parameters to (b) jsp/UpdateGlobalSettings.jsp; and the (8) haid and (9) returnpath parameters to (c) showTile.do.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39914" source="XF">manageengine-multiple-xss(39914)</ref>
      <ref url="http://www.securityfocus.com/bid/27443" source="BID">27443</ref>
      <ref url="http://secunia.com/advisories/28332" source="SECUNIA" adv="1">28332</ref>
    </refs>
    <vuln_soft>
      <prod vendor="manageengine" name="applications_manager">
        <vers num="8.1_build_8100"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0475" published="2008-01-29" name="CVE-2008-0475" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ManageEngine Applications Manager 8.1 build 8100 allows remote attackers to obtain sensitive information ( Home->Summary) via an invalid URI, as demonstrated by the "/-" URI.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39917" source="XF">manageengine-home-information-disclosure(39917)</ref>
      <ref url="http://www.securityfocus.com/bid/27443" source="BID">27443</ref>
      <ref url="http://secunia.com/advisories/28332" source="SECUNIA" adv="1">28332</ref>
    </refs>
    <vuln_soft>
      <prod vendor="manageengine" name="applications_manager">
        <vers num="8.1_build_8100"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0476" published="2008-01-29" name="CVE-2008-0476" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">ManageEngine Applications Manager 8.1 build 8100 does not check authentication for monitorType.do and unspecified other pages, which allows remote attackers to obtain sensitive information and change settings via unspecified vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39915" source="XF">manageengine-checks-security-bypass(39915)</ref>
      <ref url="http://www.securityfocus.com/bid/27443" source="BID">27443</ref>
      <ref url="http://secunia.com/advisories/28332" source="SECUNIA" adv="1">28332</ref>
    </refs>
    <vuln_soft>
      <prod vendor="manageengine" name="applications_manager">
        <vers num="8.1_build_8100"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0477" published="2008-01-29" name="CVE-2008-0477" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the QMPUpgrade.Upgrade.1 ActiveX control in QMPUpgrade.dll 1.0.0.1 in Move Networks Upgrade Manager allows remote attackers to execute arbitrary code via a long first argument to the Upgrade method.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39913" source="XF">movenetworks-qmpupgrade-bo(39913)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0274" source="VUPEN">ADV-2008-0274</ref>
      <ref url="http://www.securityfocus.com/bid/27438" source="BID">27438</ref>
      <ref url="http://www.milw0rm.com/exploits/4979" source="MILW0RM">4979</ref>
      <ref url="http://secunia.com/advisories/28647" source="SECUNIA" adv="1">28647</ref>
      <ref url="http://www.securitytracker.com/id?1019270" source="SECTRACK">1019270</ref>
    </refs>
    <vuln_soft>
      <prod vendor="move_networks_inc" name="move_media_player">
        <vers num="1.0.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0478" published="2008-01-29" name="CVE-2008-0478" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in SetCMS 3.6.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the set parameter, as demonstrated by sending a certain CLIENT_IP HTTP header in an enter action to index.php, and injecting PHP sequences into files/enter.set, which is then included by index.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39864" source="XF">setcms-index-file-include(39864)</ref>
      <ref url="http://www.securityfocus.com/bid/27407" source="BID">27407</ref>
      <ref url="http://www.milw0rm.com/exploits/4962" source="MILW0RM">4962</ref>
    </refs>
    <vuln_soft>
      <prod vendor="setcms" name="setcms">
        <vers num="3.6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0479" published="2008-01-29" name="CVE-2008-0479" modified="2009-09-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz NewsPad 1.02 allows remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39863" source="XF">newspad-rte-directory-traversal(39863)</ref>
      <ref url="http://www.webwizguide.com/webwiznewspad/kb/release_notes.asp" source="CONFIRM">http://www.webwizguide.com/webwiznewspad/kb/release_notes.asp</ref>
      <ref url="http://www.securitytracker.com/id?1019268" source="SECTRACK">1019268</ref>
      <ref url="http://www.securityfocus.com/bid/27419" source="BID">27419</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486869/100/0/threaded" source="BUGTRAQ">20080123 Web Wiz NewsPad Directory traversal</ref>
      <ref url="http://www.milw0rm.com/exploits/4972" source="MILW0RM">4972</ref>
      <ref url="http://www.bugreport.ir/?/30" source="MISC">http://www.bugreport.ir/?/30</ref>
      <ref url="http://secunia.com/advisories/28416" source="SECUNIA" adv="1">28416</ref>
      <ref url="http://securityreason.com/securityalert/3588" source="SREASON">3588</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web_wiz" name="newspad">
        <vers num="1.02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0480" published="2008-01-29" name="CVE-2008-0480" modified="2009-09-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in Web Wiz Forums 9.07 and earlier allow remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter to (1) RTE_file_browser.asp or (2) file_browser.asp.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39856" source="XF">webwiz-rte-filebrowser-directory-traversal(39856)</ref>
      <ref url="http://www.webwizguide.com/webwizforums/kb/release_notes.asp" source="CONFIRM">http://www.webwizguide.com/webwizforums/kb/release_notes.asp</ref>
      <ref url="http://www.securitytracker.com/id?1019266" source="SECTRACK">1019266</ref>
      <ref url="http://www.securityfocus.com/bid/27419" source="BID">27419</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486866/100/0/threaded" source="BUGTRAQ">20080123 Web Wiz Forums Directory traversal</ref>
      <ref url="http://www.milw0rm.com/exploits/4970" source="MILW0RM">4970</ref>
      <ref url="http://www.bugreport.ir/?/29" source="MISC">http://www.bugreport.ir/?/29</ref>
      <ref url="http://secunia.com/advisories/28601" source="SECUNIA" adv="1">28601</ref>
      <ref url="http://securityreason.com/securityalert/3589" source="SREASON">3589</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web_wiz" name="web_wiz_forums">
        <vers prev="1" num="9.07"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0481" published="2008-01-29" name="CVE-2008-0481" modified="2009-09-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter in a save action.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39868" source="XF">editor-rte-directory-traversal(39868)</ref>
      <ref url="http://www.webwizguide.com/webwizrichtexteditor/kb/release_notes.asp" source="CONFIRM">http://www.webwizguide.com/webwizrichtexteditor/kb/release_notes.asp</ref>
      <ref url="http://www.securityfocus.com/bid/27419" source="BID">27419</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486868/100/0/threaded" source="BUGTRAQ">20080123 Web Wiz Rich Text Editor Directory traversal + HTM/HTML filecreation on the server</ref>
      <ref url="http://www.milw0rm.com/exploits/4971" source="MILW0RM">4971</ref>
      <ref url="http://www.bugreport.ir/?/31" source="MISC">http://www.bugreport.ir/?/31</ref>
      <ref url="http://securitytracker.com/id?1019267" source="SECTRACK">1019267</ref>
      <ref url="http://secunia.com/advisories/28639" source="SECUNIA" adv="1">28639</ref>
      <ref url="http://securityreason.com/securityalert/3584" source="SREASON">3584</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web_wiz" name="rich_text_editor">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0485" published="2008-02-05" name="CVE-2008-0485" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Array index error in libmpdemux/demux_mov.c in MPlayer 1.0 rc2 and earlier might allow remote attackers to execute arbitrary code via a QuickTime MOV file with a crafted stsc atom tag.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0406/references" source="VUPEN">ADV-2008-0406</ref>
      <ref url="http://www.securityfocus.com/bid/27499" source="BID">27499</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487500/100/0/threaded" source="BUGTRAQ">20080204 CORE-2008-0122: MPlayer arbitrary pointer dereference</ref>
      <ref url="http://www.securitytracker.com/id?1019299" source="SECTRACK">1019299</ref>
      <ref url="http://www.mplayerhq.hu/design7/news.html" source="CONFIRM">http://www.mplayerhq.hu/design7/news.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:045" source="MANDRIVA">MDVSA-2008:045</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1496" source="DEBIAN">DSA-1496</ref>
      <ref url="http://www.coresecurity.com/?action=item&amp;id=2102" source="MISC">http://www.coresecurity.com/?action=item&amp;id=2102</ref>
      <ref url="http://securityreason.com/securityalert/3607" source="SREASON">3607</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200803-16.xml" source="GENTOO">GLSA-200803-16</ref>
      <ref url="http://secunia.com/advisories/29307" source="SECUNIA">29307</ref>
      <ref url="http://secunia.com/advisories/28956" source="SECUNIA">28956</ref>
      <ref url="http://secunia.com/advisories/28955" source="SECUNIA">28955</ref>
      <ref url="http://secunia.com/advisories/28779" source="SECUNIA">28779</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060032.html" source="FULLDISC">20080204 CORE-2008-0122: MPlayer arbitrary pointer dereference</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mplayer" name="mplayer">
        <vers prev="1" num="1.02rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0486" published="2008-02-05" name="CVE-2008-0486" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Array index vulnerability in libmpdemux/demux_audio.c in MPlayer 1.0rc2 and SVN before r25917, and possibly earlier versions, as used in Xine-lib 1.1.10, might allow remote attackers to execute arbitrary code via a crafted FLAC tag, which triggers a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00442.html" source="FEDORA">FEDORA-2008-1581</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00395.html" source="FEDORA">FEDORA-2008-1543</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=431541" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=431541</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0421" source="VUPEN">ADV-2008-0421</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0406/references" source="VUPEN">ADV-2008-0406</ref>
      <ref url="http://www.ubuntu.com/usn/usn-635-1" source="UBUNTU">USN-635-1</ref>
      <ref url="http://www.securityfocus.com/bid/27441" source="BID">27441</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487501/100/0/threaded" source="BUGTRAQ">20080204 CORE-2007-1218: MPlayer 1.0rc2 buffer overflow vulnerability</ref>
      <ref url="http://www.mplayerhq.hu/design7/news.html" source="CONFIRM">http://www.mplayerhq.hu/design7/news.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:046" source="MANDRIVA">MDVSA-2008:046</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:045" source="MANDRIVA">MDVSA-2008:045</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1536" source="DEBIAN">DSA-1536</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1496" source="DEBIAN">DSA-1496</ref>
      <ref url="http://www.coresecurity.com/?action=item&amp;id=2103" source="MISC">http://www.coresecurity.com/?action=item&amp;id=2103</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=9655&amp;release_id=574735" source="CONFIRM">http://sourceforge.net/project/shownotes.php?group_id=9655&amp;release_id=574735</ref>
      <ref url="http://securityreason.com/securityalert/3608" source="SREASON">3608</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200803-16.xml" source="GENTOO">GLSA-200803-16</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200802-12.xml" source="GENTOO">GLSA-200802-12</ref>
      <ref url="http://secunia.com/advisories/31393" source="SECUNIA">31393</ref>
      <ref url="http://secunia.com/advisories/29601" source="SECUNIA" adv="1">29601</ref>
      <ref url="http://secunia.com/advisories/29323" source="SECUNIA" adv="1">29323</ref>
      <ref url="http://secunia.com/advisories/29307" source="SECUNIA" adv="1">29307</ref>
      <ref url="http://secunia.com/advisories/29141" source="SECUNIA" adv="1">29141</ref>
      <ref url="http://secunia.com/advisories/28989" source="SECUNIA" adv="1">28989</ref>
      <ref url="http://secunia.com/advisories/28956" source="SECUNIA" adv="1">28956</ref>
      <ref url="http://secunia.com/advisories/28955" source="SECUNIA" adv="1">28955</ref>
      <ref url="http://secunia.com/advisories/28918" source="SECUNIA" adv="1">28918</ref>
      <ref url="http://secunia.com/advisories/28801" source="SECUNIA" adv="1">28801</ref>
      <ref url="http://secunia.com/advisories/28779" source="SECUNIA" adv="1">28779</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html" source="SUSE">SUSE-SR:2008:006</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060033.html" source="FULLDISC">20080204 CORE-2007-1218: MPlayer 1.0rc2 buffer overflow vulnerability</ref>
      <ref url="http://bugs.xine-project.org/show_bug.cgi?id=38" source="CONFIRM">http://bugs.xine-project.org/show_bug.cgi?id=38</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=209106" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=209106</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mplayer" name="mplayer">
        <vers num="1.02rc2"/>
      </prod>
      <prod vendor="xine" name="xine-lib">
        <vers num="1.1.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0487" published="2008-01-30" name="CVE-2008-0487" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in login.asp in ASPired2Protect allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39989" source="XF">aspired2protect-login-sql-injection(39989)</ref>
      <ref url="http://www.securityfocus.com/bid/27474" source="BID">27474</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487137/100/0/threaded" source="BUGTRAQ">20080126 ASPired2Protect bypass</ref>
      <ref url="http://secunia.com/advisories/28653" source="SECUNIA" adv="1">28653</ref>
      <ref url="http://securityreason.com/securityalert/3598" source="SREASON">3598</ref>
    </refs>
    <vuln_soft>
      <prod vendor="the_net_guys" name="aspired2protect">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0488" published="2008-01-30" name="CVE-2008-0488" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in tseekdir.cgi in VB Marketing allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the location parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39970" source="XF">vbmarketing-tseekdir-file-include(39970)</ref>
      <ref url="http://www.securityfocus.com/bid/27475" source="BID">27475</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487174/100/0/threaded" source="BUGTRAQ">20080128 VB Marketing "tseekdir.cgi" Local File Inclusion</ref>
      <ref url="http://securityreason.com/securityalert/3596" source="SREASON">3596</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vb_marketing" name="vb_marketing">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0489" published="2008-01-30" name="CVE-2008-0489" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in install.php in Clansphere 2007.4.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39977" source="XF">clansphere-install-directory-traversal(39977)</ref>
      <ref url="http://www.securityfocus.com/bid/27471" source="BID">27471</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487132/100/0/threaded" source="BUGTRAQ">20080127 ClanSphere 2007.4.4 Remote File Disclosure Vulnerability.</ref>
      <ref url="http://securityreason.com/securityalert/3597" source="SREASON">3597</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clansphere" name="clansphere">
        <vers num="2007.4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0490" published="2008-01-30" name="CVE-2008-0490" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in functions/editevent.php in the WP-Cal 0.3 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39966" source="XF">wpcal-editevent-sql-injection(39966)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0348" source="VUPEN">ADV-2008-0348</ref>
      <ref url="http://www.securityfocus.com/bid/27465" source="BID">27465</ref>
      <ref url="http://www.milw0rm.com/exploits/4992" source="MILW0RM">4992</ref>
      <ref url="http://secunia.com/advisories/28683" source="SECUNIA" adv="1">28683</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wp_cal_plugin">
        <vers num="0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0491" published="2008-01-30" name="CVE-2008-0491" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in fim_rss.php in the fGallery 2.4.1 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the album parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39964" source="XF">fgallery-fimrss-sql-injection(39964)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0349" source="VUPEN">ADV-2008-0349</ref>
      <ref url="http://www.securityfocus.com/bid/27464" source="BID">27464</ref>
      <ref url="http://www.milw0rm.com/exploits/4993" source="MILW0RM">4993</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="fgallery_plugin">
        <vers num="2.4.1"/>
      </prod>
      <prod vendor="wordpress" name="wordpress">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0492" published="2008-01-30" name="CVE-2008-0492" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the Persits.XUpload.2 ActiveX control in XUpload.ocx 3.0.0.4 and earlier in Persits XUpload 3.0 allows remote attackers to execute arbitrary code via a long argument to the AddFile method.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39967" source="XF">persits-xupload-bo(39967)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0315" source="VUPEN">ADV-2008-0315</ref>
      <ref url="http://www.securityfocus.com/bid/27456" source="BID">27456</ref>
      <ref url="http://www.milw0rm.com/exploits/4987" source="MILW0RM">4987</ref>
      <ref url="http://secunia.com/advisories/28660" source="SECUNIA" adv="1">28660</ref>
    </refs>
    <vuln_soft>
      <prod vendor="persits" name="xupload">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0493" published="2008-01-30" name="CVE-2008-0493" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">fpx.dll 3.9.8.0 in the FlashPix plugin for IrfanView 4.10 allows remote attackers to execute arbitrary code via a crafted FlashPix (.FPX) file, which triggers heap corruption.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0318" source="VUPEN">ADV-2008-0318</ref>
      <ref url="http://www.securityfocus.com/bid/27479" source="BID">27479</ref>
      <ref url="http://www.milw0rm.com/exploits/4998" source="MILW0RM">4998</ref>
      <ref url="http://secunia.com/advisories/28688" source="SECUNIA" adv="1">28688</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40012" source="XF">irfanview-flashpix-bo(40012)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="irfanview" name="irfanview">
        <vers num="4.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0494" published="2008-01-30" name="CVE-2008-0494" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in vpnum/userslist.php in Endian Firewall 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the psearch parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27477" source="BID">27477</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/27477.html" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/27477.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="endian" name="firewall">
        <vers num="2.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0495" published="2008-01-30" name="CVE-2008-0495" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Pegasus CIM Server in IBM Hardware Management Console (HMC) 7 R3.2.0 allows remote attackers to cause a denial of service via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://www14.software.ibm.com/webapp/set2/sas/f/hmc/power6/install/v7.Readme.html" source="CONFIRM">https://www14.software.ibm.com/webapp/set2/sas/f/hmc/power6/install/v7.Readme.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0638" source="VUPEN">ADV-2008-0638</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0323" source="VUPEN">ADV-2008-0323</ref>
      <ref url="http://www.securityfocus.com/bid/27484" source="BID">27484</ref>
      <ref url="http://secunia.com/advisories/28667" source="SECUNIA" adv="1">28667</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40021" source="XF">hmc-pegasus-cim-dos(40021)</ref>
      <ref url="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=4129" source="CONFIRM">http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=4129</ref>
      <ref url="http://www.securitytracker.com/id?1019280" source="SECTRACK">1019280</ref>
      <ref url="http://secunia.com/advisories/29056" source="SECUNIA">29056</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="hardware_management_console">
        <vers num="7.3.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0496" published="2008-01-30" name="CVE-2008-0496" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in AmpJuke 0.7.0 allows remote attackers to inject arbitrary web script or HTML via the limit parameter in a search action.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0332" source="VUPEN">ADV-2008-0332</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487258/100/0/threaded" source="BUGTRAQ">20080129 AmpJuke-0.7.0 (index.php) Xss VuLn.</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40023" source="XF">juke-index-xss(40023)</ref>
      <ref url="http://www.securityfocus.com/bid/27498" source="BID">27498</ref>
      <ref url="http://securityreason.com/securityalert/3594" source="SREASON">3594</ref>
      <ref url="http://secunia.com/advisories/28661" source="SECUNIA">28661</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ampjuke" name="ampjuke">
        <vers num="0.7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0497" published="2008-01-30" name="CVE-2008-0497" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in action.php in Nucleus CMS 3.31 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO, which is not quoted when processing PHP_SELF.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487255/100/0/threaded" source="BUGTRAQ" patch="1">20080129 [!!FIX Information ] Nucleus 3.31 XSS in path</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=66479&amp;release_id=572117" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=66479&amp;release_id=572117</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0369" source="VUPEN">ADV-2008-0369</ref>
      <ref url="http://www.securityfocus.com/bid/27492" source="BID">27492</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487252/100/0/threaded" source="BUGTRAQ">20080129 Nucleus 3.31 XSS in path</ref>
      <ref url="http://www.nucleuscms.org/item/3047" source="CONFIRM">http://www.nucleuscms.org/item/3047</ref>
      <ref url="http://securityreason.com/securityalert/3593" source="SREASON">3593</ref>
      <ref url="http://secunia.com/advisories/28680" source="SECUNIA">28680</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nucleus_cms" name="nucleus_cms">
        <vers num="3.31"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0498" published="2008-01-30" name="CVE-2008-0498" modified="2012-10-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in main_bigware_53.tpl.php in Bigware Shop 2.0 allows remote attackers to execute arbitrary SQL commands via the pollid parameter in a results action to main_bigware_53.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/40010" source="XF">bigwareshop-mainbigware-sql-injection(40010)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0351" source="VUPEN">ADV-2008-0351</ref>
      <ref url="http://www.securityfocus.com/bid/27489" source="BID">27489</ref>
      <ref url="http://www.milw0rm.com/exploits/5002" source="MILW0RM">5002</ref>
      <ref url="http://secunia.com/advisories/28691" source="SECUNIA">28691</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bigware" name="bigware_shop">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0499" published="2008-01-30" name="CVE-2008-0499" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Mambo LaiThai 4.5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27483" source="BID" patch="1">27483</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=192544&amp;release_id=571300" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=192544&amp;release_id=571300</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0316" source="VUPEN">ADV-2008-0316</ref>
      <ref url="http://secunia.com/advisories/28652" source="SECUNIA" adv="1">28652</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40013" source="XF">mambo-laithai-unspecified-sql-injection(40013)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mamboxchange" name="laithai">
        <vers num="4.5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0500" published="2008-01-30" name="CVE-2008-0500" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Mambo LaiThai 4.5.5 have unknown impact and attack vectors related to (1) mod_login and (2) mod_template_chooser.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27483" source="BID" patch="1">27483</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0316" source="VUPEN">ADV-2008-0316</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=192544&amp;release_id=571300" source="CONFIRM">http://sourceforge.net/project/shownotes.php?group_id=192544&amp;release_id=571300</ref>
      <ref url="http://secunia.com/advisories/28652" source="SECUNIA" adv="1">28652</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40014" source="XF">mambo-laithai-multiple-unspecified(40014)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mamboxchange" name="laithai">
        <vers num="4.5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0501" published="2008-01-30" name="CVE-2008-0501" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in phpMyClub 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page_courante parameter to the top-level URI.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/40007" source="XF">phpmyclub-pagecourante-file-include(40007)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0350" source="VUPEN">ADV-2008-0350</ref>
      <ref url="http://www.securityfocus.com/bid/27480" source="BID">27480</ref>
      <ref url="http://www.milw0rm.com/exploits/5000" source="MILW0RM">5000</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sourceforge" name="phpmyclub">
        <vers num="0.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0502" published="2008-01-31" name="CVE-2008-0502" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in templates/Official/part_userprofile.php in Connectix Boards 0.8.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the template_path parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/40040" source="XF">connectixboards-templatepath-file-include(40040)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0363" source="VUPEN">ADV-2008-0363</ref>
      <ref url="http://www.securityfocus.com/bid/27506" source="BID">27506</ref>
      <ref url="http://www.milw0rm.com/exploits/5012" source="MILW0RM">5012</ref>
      <ref url="http://secunia.com/advisories/28704" source="SECUNIA" adv="1">28704</ref>
    </refs>
    <vuln_soft>
      <prod vendor="connectix" name="connectix_boards">
        <vers num="0.8.1"/>
        <vers prev="1" num="0.8.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0503" published="2008-01-31" name="CVE-2008-0503" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Eval injection vulnerability in admin/op/disp.php in Netwerk Smart Publisher 1.0.1 allows remote attackers to execute arbitrary PHP code via the filedata parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0352" source="VUPEN">ADV-2008-0352</ref>
      <ref url="http://www.securityfocus.com/bid/27488" source="BID">27488</ref>
      <ref url="http://www.milw0rm.com/exploits/5003" source="MILW0RM">5003</ref>
      <ref url="http://secunia.com/advisories/28685" source="SECUNIA" adv="1">28685</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netwerk" name="smart_publisher">
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0504" published="2008-01-31" name="CVE-2008-0504" modified="2009-09-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote authen ticated administrators to execute arbitrary SQL commands via the (1) albumid, (2) startpic, and (3) numpics parameters to util.php; and (4) cid_array parameter to reviewcom.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27509" source="BID" patch="1">27509</ref>
      <ref url="http://coppermine-gallery.net/forum/index.php?topic=50103.0" source="CONFIRM" patch="1">http://coppermine-gallery.net/forum/index.php?topic=50103.0</ref>
      <ref url="http://www.waraxe.us/advisory-66.html" source="MISC">http://www.waraxe.us/advisory-66.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0367" source="VUPEN" adv="1">ADV-2008-0367</ref>
      <ref url="http://www.securitytracker.com/id?1019285" source="SECTRACK">1019285</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487351/100/200/threaded" source="BUGTRAQ">20080131 [waraxe-2008-SA#066] - Multiple Vulnerabilities in Coppermine 1.4.14</ref>
      <ref url="http://secunia.com/advisories/28682" source="SECUNIA" adv="1">28682</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coppermine-gallery" name="coppermine_photo_gallery">
        <vers num="1.0" edition="rc3"/>
        <vers num="1.1" edition="beta_2"/>
        <vers num="1.1.0"/>
        <vers num="1.2"/>
        <vers num="1.2.0" edition="rc2"/>
        <vers num="1.2.1" edition="b"/>
        <vers num="1.2.1" edition="b-nuke"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.5"/>
        <vers num="1.4"/>
        <vers num="1.4.0" edition="alpha"/>
        <vers num="1.4.0" edition="beta"/>
        <vers num="1.4.1" edition="beta"/>
        <vers num="1.4.10"/>
        <vers num="1.4.11"/>
        <vers num="1.4.12"/>
        <vers num="1.4.13"/>
        <vers prev="1" num="1.4.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0505" published="2008-01-31" name="CVE-2008-0505" modified="2009-09-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote attackers to inject arbitrary web script or HTML via the (1) h and (2) t parameters.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27511" source="BID" patch="1">27511</ref>
      <ref url="http://coppermine-gallery.net/forum/index.php?topic=50103.0" source="CONFIRM" patch="1">http://coppermine-gallery.net/forum/index.php?topic=50103.0</ref>
      <ref url="http://www.waraxe.us/advisory-66.html" source="MISC">http://www.waraxe.us/advisory-66.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0367" source="VUPEN" adv="1">ADV-2008-0367</ref>
      <ref url="http://www.securitytracker.com/id?1019285" source="SECTRACK">1019285</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487351/100/200/threaded" source="BUGTRAQ">20080131 [waraxe-2008-SA#066] - Multiple Vulnerabilities in Coppermine 1.4.14</ref>
      <ref url="http://secunia.com/advisories/28682" source="SECUNIA" adv="1">28682</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coppermine" name="coppermine_photo_gallery">
        <vers num="1.4.10"/>
        <vers num="1.4.11"/>
        <vers num="1.4.12"/>
        <vers num="1.4.13"/>
        <vers prev="1" num="1.4.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0506" published="2008-01-31" name="CVE-2008-0506" modified="2009-09-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) quality, (2) angle, or (3) clipval parameter to picEditor.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27512" source="BID" patch="1">27512</ref>
      <ref url="http://coppermine-gallery.net/forum/index.php?topic=50103.0" source="CONFIRM" patch="1">http://coppermine-gallery.net/forum/index.php?topic=50103.0</ref>
      <ref url="http://www.waraxe.us/advisory-65.html" source="MISC">http://www.waraxe.us/advisory-65.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0367" source="VUPEN" adv="1">ADV-2008-0367</ref>
      <ref url="http://www.securitytracker.com/id?1019286" source="SECTRACK">1019286</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487310/100/200/threaded" source="BUGTRAQ">20080130 [waraxe-2008-SA#065] - Remote Shell Command Execution in Coppermine 1.4.14</ref>
      <ref url="http://www.milw0rm.com/exploits/5019" source="MILW0RM">5019</ref>
      <ref url="http://secunia.com/advisories/28682" source="SECUNIA" adv="1">28682</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coppermine" name="coppermine_photo_gallery">
        <vers prev="1" num="1.4.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0507" published="2008-01-31" name="CVE-2008-0507" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in adclick.php in the AdServe 0.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0364" source="VUPEN">ADV-2008-0364</ref>
      <ref url="http://www.securityfocus.com/bid/27504" source="BID">27504</ref>
      <ref url="http://www.milw0rm.com/exploits/5013" source="MILW0RM">5013</ref>
      <ref url="http://secunia.com/advisories/28708" source="SECUNIA" adv="1">28708</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40045" source="XF">adserve-adclick-sql-injection(40045)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="adserve">
        <vers num="0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0508" published="2008-01-31" name="CVE-2008-0508" modified="2011-03-07" discovered="2008-01-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in deans_permalinks_migration.php in the Dean's Permalinks Migration 1.0 plugin for WordPress allows remote attackers to modify the oldstructure (aka dean_pm_config[oldstructure]) configuration setting as administrators via the old_struct parameter in a deans_permalinks_migration.php action to wp-admin/options-general.php, as demonstrated by placing an XSS sequence in this setting.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://g30rg3x.com/xsrf-bajo-deans-permalinks-migration-10" source="MISC" patch="1">http://g30rg3x.com/xsrf-bajo-deans-permalinks-migration-10</ref>
      <ref url="http://g30rg3x.com/wp-files/dpm_11gx.zip" source="MISC" patch="1">http://g30rg3x.com/wp-files/dpm_11gx.zip</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39845" source="XF">permalinks-deanpmconfig-csrf(39845)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0281" source="VUPEN">ADV-2008-0281</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486840/100/0/threaded" source="BUGTRAQ">20080122 XSRF under Dean&amp;acirc;??s Permalinks Migration 1.0</ref>
      <ref url="http://securityreason.com/securityalert/3595" source="SREASON">3595</ref>
      <ref url="http://secunia.com/advisories/28593" source="SECUNIA" adv="1">28593</ref>
      <ref url="http://packetstorm.linuxsecurity.com/0801-advisories/deans-xsrf.txt" source="MISC">http://packetstorm.linuxsecurity.com/0801-advisories/deans-xsrf.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="permalinks_migration_plugin">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0509" published="2008-01-31" name="CVE-2008-0509" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:N/I:N/A:C)" CVSS_score="4.4" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="2.7" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Multiple buffer overflows in IBM AIX 4.3 allow remote attackers to cause a denial of service (crash) or possibly gain privileges via a long argument to (1) piox25, related to piox25.c; or (2) piox25remote, related to piox25remote.sh.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0324" source="VUPEN">ADV-2008-0324</ref>
      <ref url="http://www.securityfocus.com/bid/27510" source="BID">27510</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IZ13739" source="AIXAPAR">IZ13739</ref>
      <ref url="http://secunia.com/advisories/28600" source="SECUNIA" adv="1">28600</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5796" source="OVAL">oval:org.mitre.oval:def:5796</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0510" published="2008-01-31" name="CVE-2008-0510" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in the Newsletter (com_newsletter) component for Mambo 4.5 and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/40036" source="XF">newsletter-index-sql-injection(40036)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0354" source="VUPEN">ADV-2008-0354</ref>
      <ref url="http://www.securityfocus.com/bid/27502" source="BID">27502</ref>
      <ref url="http://www.milw0rm.com/exploits/5007" source="MILW0RM">5007</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="com_newsletter">
        <vers num=""/>
      </prod>
      <prod vendor="mambo" name="com_newsletter">
        <vers num=""/>
      </prod>
      <prod vendor="mambo" name="mambo">
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0511" published="2008-01-31" name="CVE-2008-0511" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in the MaMML (com_mamml) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/40037" source="XF">mamml-index-sql-injection(40037)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0356" source="VUPEN">ADV-2008-0356</ref>
      <ref url="http://www.securityfocus.com/bid/27503" source="BID">27503</ref>
      <ref url="http://www.milw0rm.com/exploits/5009" source="MILW0RM">5009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="com_mamml">
        <vers num=""/>
      </prod>
      <prod vendor="mambo" name="com_mamml">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0512" published="2008-01-31" name="CVE-2008-0512" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in the fq (com_fq) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/40035" source="XF">fq-index-sql-injection(40035)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0355" source="VUPEN">ADV-2008-0355</ref>
      <ref url="http://www.securityfocus.com/bid/27501" source="BID">27501</ref>
      <ref url="http://www.milw0rm.com/exploits/5008" source="MILW0RM">5008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="com_fq">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0513" published="2008-01-31" name="CVE-2008-0513" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in parser/include/class.cache_phpcms.php in phpCMS 1.2.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to parser/parser.php, as demonstrated by a filename ending with %00.gif, a different vector than CVE-2005-1840.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/40017" source="XF">phpcms-parser-directory-traversal(40017)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0353" source="VUPEN">ADV-2008-0353</ref>
      <ref url="http://www.securityfocus.com/bid/27495" source="BID">27495</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487254/100/0/threaded" source="BUGTRAQ">20080129 Re: Remote File Disclosure in phpCMS 1.2.2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487251/100/0/threaded" source="BUGTRAQ">20080129 Remote File Disclosure in phpCMS 1.2.2</ref>
      <ref url="http://www.milw0rm.com/exploits/5006" source="MILW0RM">5006</ref>
      <ref url="http://secunia.com/advisories/28709" source="SECUNIA">28709</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpcms" name="phpcms">
        <vers num="1.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0514" published="2008-01-31" name="CVE-2008-0514" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in the Glossary (com_glossary) 2.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a display action.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0357" source="VUPEN">ADV-2008-0357</ref>
      <ref url="http://www.securityfocus.com/bid/27505" source="BID">27505</ref>
      <ref url="http://www.milw0rm.com/exploits/5010" source="MILW0RM">5010</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40038" source="XF">glossary-index-sql-injection(40038)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="glossary">
        <vers num="2.0"/>
      </prod>
      <prod vendor="mambo" name="glossary">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0515" published="2008-01-31" name="CVE-2008-0515" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in the musepoes (com_musepoes) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an answer action.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0358" source="VUPEN">ADV-2008-0358</ref>
      <ref url="http://www.securityfocus.com/bid/27507" source="BID">27507</ref>
      <ref url="http://www.milw0rm.com/exploits/5011" source="MILW0RM">5011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="musepoes_component">
        <vers num=""/>
      </prod>
      <prod vendor="mambo" name="musepoes_component">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0516" published="2008-01-31" name="CVE-2008-0516" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in spaw/dialogs/confirm.php in SQLiteManager 1.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/28642" source="SECUNIA" adv="1">28642</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40065" source="XF">sqlitemanager-confirm-file-include(40065)</ref>
      <ref url="http://www.securityfocus.com/bid/27515" source="BID">27515</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sqlite_manager" name="sqlite_manager">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0517" published="2008-01-31" name="CVE-2008-0517" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in the Darko Selesi EstateAgent (com_estateagent) 0.1 component for Mambo 4.5.x and Joomla! allows remote attackers to execute arbitrary SQL commands via the objid parameter in a contact showObject action.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0362" source="VUPEN">ADV-2008-0362</ref>
      <ref url="http://www.milw0rm.com/exploits/5016" source="MILW0RM">5016</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40060" source="XF">estateagent-index-sql-injection(40060)</ref>
      <ref url="http://www.securityfocus.com/bid/27520" source="BID">27520</ref>
    </refs>
    <vuln_soft>
      <prod vendor="darko_selesi" name="estateagent">
        <vers num="0.1"/>
      </prod>
      <prod vendor="joomla" name="joomla">
        <vers num=""/>
      </prod>
      <prod vendor="mambo" name="mambo">
        <vers num="4.5"/>
        <vers num="4.5.0.2"/>
        <vers num="4.5.1.3"/>
        <vers num="4.5.1_1.0.9"/>
        <vers num="4.5.1_beta"/>
        <vers num="4.5.1_beta2"/>
        <vers num="4.5.1a"/>
        <vers num="4.5.2"/>
        <vers num="4.5.2.1"/>
        <vers num="4.5.2.2"/>
        <vers num="4.5.2.3"/>
        <vers num="4.5.3h"/>
        <vers num="4.5.4"/>
        <vers num="4.5_1.0.0"/>
        <vers num="4.5_1.0.1"/>
        <vers num="4.5_1.0.2"/>
        <vers num="4.5_1.0.3_beta"/>
        <vers num="4.5_1.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0518" published="2008-01-31" name="CVE-2008-0518" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in the Recipes (com_recipes) 1.00 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0360" source="VUPEN">ADV-2008-0360</ref>
      <ref url="http://www.milw0rm.com/exploits/5014" source="MILW0RM">5014</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40064" source="XF">recipes-index-sql-injection(40064)</ref>
      <ref url="http://www.securityfocus.com/bid/27519" source="BID">27519</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="com_recipes">
        <vers num="1.00"/>
      </prod>
      <prod vendor="mambo" name="com_recipes">
        <vers num="1.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0519" published="2008-01-31" name="CVE-2008-0519" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in the Atapin Jokes (com_jokes) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a CatView action.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0361" source="VUPEN">ADV-2008-0361</ref>
      <ref url="http://www.milw0rm.com/exploits/5015" source="MILW0RM">5015</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40067" source="XF">jokes-index-sql-injection(40067)</ref>
      <ref url="http://www.securityfocus.com/bid/27522" source="BID">27522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="com_jokes">
        <vers num="1.0"/>
      </prod>
      <prod vendor="mambo" name="com_jokes">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0520" published="2008-01-31" name="CVE-2008-0520" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in main.php in the WassUp plugin 1.4 through 1.4.3 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) from_date or (2) to_date parameter to spy.php.</descript>
      <descript source="nvd">Additional research found the following links:

http://secunia.com/advisories/28702/

http://www.securityfocus.com/bid/27525</descript>
    </desc>
    <sols>
      <sol source="nvd">Additional research found the following link:
http://downloads.wordpress.org/plugin/wassup.1.4.3a.zip</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.wpwp.org/archives/warning-security-bug-in-version/" source="CONFIRM">http://www.wpwp.org/archives/warning-security-bug-in-version/</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0365" source="VUPEN">ADV-2008-0365</ref>
      <ref url="http://www.securityfocus.com/bid/27525" source="BID">27525</ref>
      <ref url="http://www.milw0rm.com/exploits/5017" source="MILW0RM">5017</ref>
      <ref url="http://secunia.com/advisories/28702" source="SECUNIA" adv="1">28702</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wassup_plugin">
        <vers num="1.4"/>
        <vers prev="1" num="1.4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0521" published="2008-01-31" name="CVE-2008-0521" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to read arbitrary files via a .. (dot dot) in the uri parameter to dispatcher.php in (1) examples/dispatcher/framework/, (2) examples/dispatcher/, (3) examples/wizard/, and (4) PHP/, different vectors than CVE-2008-0545.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/40008" source="XF">bubbling-dispatcher-directory-traversal(40008)</ref>
      <ref url="http://www.securityfocus.com/bid/27482" source="BID">27482</ref>
      <ref url="http://www.milw0rm.com/exploits/5001" source="MILW0RM">5001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bubbling_library" name="bubbling_library">
        <vers num="1.32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0522" published="2008-01-31" name="CVE-2008-0522" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in multiple Hal Networks shopping-cart products allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0368" source="VUPEN">ADV-2008-0368</ref>
      <ref url="http://www.hal9800.com/home/bug/20080129.html" source="CONFIRM">http://www.hal9800.com/home/bug/20080129.html</ref>
      <ref url="http://www.hal9800.com/home/bug/20080128.html" source="CONFIRM">http://www.hal9800.com/home/bug/20080128.html</ref>
      <ref url="http://www.hal9800.com/home/bug/20080127.html" source="CONFIRM">http://www.hal9800.com/home/bug/20080127.html</ref>
      <ref url="http://www.hal9800.com/home/bug/20080123.html" source="CONFIRM">http://www.hal9800.com/home/bug/20080123.html</ref>
      <ref url="http://secunia.com/advisories/28692" source="SECUNIA">28692</ref>
      <ref url="http://jvn.jp/jp/JVN%2301162446/index.html" source="JVN">JVN#01162446</ref>
      <ref url="http://www.securityfocus.com/bid/27513" source="BID">27513</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hal_networks" name="perl__cgi_cart">
        <vers num=""/>
      </prod>
      <prod vendor="hal_networks" name="php_cart">
        <vers num=""/>
      </prod>
      <prod vendor="hal_networks" name="shop_hal_v1">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0523" published="2008-01-31" name="CVE-2008-0523" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in SoftCart.exe in SoftCart 5.1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) License_Plate, (2) License_State, (3) Ticket_Date, and (4) Ticket_Number parameters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/28675" source="SECUNIA">28675</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40061" source="XF">softcart-softcart-xss(40061)</ref>
      <ref url="http://www.securityfocus.com/bid/27524" source="BID">27524</ref>
    </refs>
    <vuln_soft>
      <prod vendor="softcart" name="softcart">
        <vers num="5.1.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0524" published="2008-01-31" name="CVE-2008-0524" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in the management interface in multiple Yamaha RT series routers allows remote attackers to change password settings and probably other configuration settings as administrators via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/40015" source="XF">yamaha-routers-http-csrf(40015)</ref>
      <ref url="http://www.securityfocus.com/bid/27491" source="BID">27491</ref>
      <ref url="http://www.rtpro.yamaha.co.jp/RT/FAQ/Security/JVN88575577.html" source="CONFIRM">http://www.rtpro.yamaha.co.jp/RT/FAQ/Security/JVN88575577.html</ref>
      <ref url="http://secunia.com/advisories/28690" source="SECUNIA">28690</ref>
      <ref url="http://jvn.jp/jp/JVN%2388575577/index.html" source="JVN">JVN#88575577</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yamaha" name="rt107e">
        <vers num=""/>
      </prod>
      <prod vendor="yamaha" name="rt52pro">
        <vers num=""/>
      </prod>
      <prod vendor="yamaha" name="rt56v">
        <vers num=""/>
      </prod>
      <prod vendor="yamaha" name="rt57i">
        <vers num=""/>
      </prod>
      <prod vendor="yamaha" name="rt58i">
        <vers num=""/>
      </prod>
      <prod vendor="yamaha" name="rt60w">
        <vers num=""/>
      </prod>
      <prod vendor="yamaha" name="rt80i">
        <vers num=""/>
      </prod>
      <prod vendor="yamaha" name="rta50i">
        <vers num=""/>
      </prod>
      <prod vendor="yamaha" name="rta52i">
        <vers num=""/>
      </prod>
      <prod vendor="yamaha" name="rta54i">
        <vers num=""/>
      </prod>
      <prod vendor="yamaha" name="rta55i">
        <vers num=""/>
      </prod>
      <prod vendor="yamaha" name="rtv700">
        <vers num=""/>
      </prod>
      <prod vendor="yamaha" name="rtw65b">
        <vers num=""/>
      </prod>
      <prod vendor="yamaha" name="rtw65i">
        <vers num=""/>
      </prod>
      <prod vendor="yamaha" name="rtx1000">
        <vers num=""/>
      </prod>
      <prod vendor="yamaha" name="rtx1100">
        <vers num=""/>
      </prod>
      <prod vendor="yamaha" name="rtx1500">
        <vers num=""/>
      </prod>
      <prod vendor="yamaha" name="srt100">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0525" published="2008-01-31" name="CVE-2008-0525" modified="2011-08-23" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">PatchLink Update client for Unix, as used by Novell ZENworks Patch Management Update Agent for Linux/Unix/Mac (LUM) 6.2094 through 6.4102 and other products, allows local users to (1) truncate arbitrary files via a symlink attack on the /tmp/patchlink.tmp file used by the logtrimmer script, and (2) execute arbitrary code via a symlink attack on the /tmp/plshutdown file used by the rebootTask script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://secure-support.novell.com/KanisaPlatform/Publishing/18/3908994_f.SAL_Public.html" source="CONFIRM">https://secure-support.novell.com/KanisaPlatform/Publishing/18/3908994_f.SAL_Public.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39958" source="XF">patchlinkupdate-reboottask-symlink(39958)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39956" source="XF">patchlinkupdate-logtrimmer-symlink(39956)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0426" source="VUPEN" adv="1">ADV-2008-0426</ref>
      <ref url="http://www.securitytracker.com/id?1019272" source="SECTRACK">1019272</ref>
      <ref url="http://www.securityfocus.com/bid/27458" source="BID">27458</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487103/100/0/threaded" source="BUGTRAQ">20080125 Two vulnerabilities for PatchLink Update Client for Unix.</ref>
      <ref url="http://support.lumension.com/scripts/rightnow.cfg/php.exe/enduser/std_adp.php?p_faqid=530" source="CONFIRM">http://support.lumension.com/scripts/rightnow.cfg/php.exe/enduser/std_adp.php?p_faqid=530</ref>
      <ref url="http://support.lumension.com/scripts/rightnow.cfg/php.exe/enduser/std_adp.php?p_faqid=528" source="CONFIRM">http://support.lumension.com/scripts/rightnow.cfg/php.exe/enduser/std_adp.php?p_faqid=528</ref>
      <ref url="http://support.lumension.com/scripts/rightnow.cfg/php.exe/enduser/std_adp.php?p_faqid=527" source="CONFIRM">http://support.lumension.com/scripts/rightnow.cfg/php.exe/enduser/std_adp.php?p_faqid=527</ref>
      <ref url="http://securityreason.com/securityalert/3599" source="SREASON">3599</ref>
      <ref url="http://secunia.com/advisories/28665" source="SECUNIA" adv="1">28665</ref>
      <ref url="http://secunia.com/advisories/28657" source="SECUNIA" adv="1">28657</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lumension_security" name="patchlink_update">
        <vers num="6.2" edition=""/>
        <vers num="6.2" edition=":linux"/>
        <vers num="6.2" edition=":unix"/>
        <vers num="6.2" edition=":mac"/>
        <vers num="6.3" edition=""/>
        <vers num="6.3" edition=":unix"/>
        <vers num="6.3" edition=":linux"/>
        <vers num="6.3" edition=":mac"/>
        <vers num="6.4" edition=""/>
        <vers num="6.4" edition=":linux"/>
        <vers num="6.4" edition=":unix"/>
        <vers num="6.4" edition=":mac"/>
      </prod>
      <prod vendor="novell" name="zenworks_patch_management_update_agent">
        <vers num="6.2" edition=""/>
        <vers num="6.2" edition=":linux"/>
        <vers num="6.2" edition=":unix"/>
        <vers num="6.2" edition=":mac"/>
        <vers num="6.3" edition=""/>
        <vers num="6.3" edition=":linux"/>
        <vers num="6.3" edition=":mac"/>
        <vers num="6.3" edition=":unix"/>
        <vers num="6.4" edition=""/>
        <vers num="6.4" edition=":linux"/>
        <vers num="6.4" edition=":mac"/>
        <vers num="6.4" edition=":unix"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0526" published="2008-02-14" name="CVE-2008-0526" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SCCP firmware allows remote attackers to cause a denial of service (reboot) via a long ICMP echo request (ping) packet.</descript>
    </desc>
    <sols>
      <sol source="nvd">In order to download the patch, login is required</sol>
    </sols>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7a.shtml" source="CISCO" patch="1">20080213 Cisco Unified IP Phone Overflow and Denial of Service Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40487" source="XF">cisco-unifiedipphone-icmp-dos(40487)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0543" source="VUPEN">ADV-2008-0543</ref>
      <ref url="http://www.securitytracker.com/id?1019407" source="SECTRACK">1019407</ref>
      <ref url="http://www.securityfocus.com/bid/27774" source="BID">27774</ref>
      <ref url="http://secunia.com/advisories/28935" source="SECUNIA" adv="1">28935</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="session_initiation_protocol_(sip)_firmware">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="skinny_client_control_protocol_(sccp)_firmware">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0527" published="2008-02-14" name="CVE-2008-0527" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The HTTP server in Cisco Unified IP Phone 7935 and 7936 running SCCP firmware allows remote attackers to cause a denial of service (reboot) via a crafted HTTP request.</descript>
    </desc>
    <sols>
      <sol source="nvd">Patch download requires login</sol>
    </sols>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7a.shtml" source="CISCO" patch="1">20080213 Cisco Unified IP Phone Overflow and Denial of Service Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40489" source="XF">cisco-unifiedipphone-httpserver-dos(40489)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0543" source="VUPEN">ADV-2008-0543</ref>
      <ref url="http://www.securitytracker.com/id?1019408" source="SECTRACK">1019408</ref>
      <ref url="http://www.securityfocus.com/bid/27774" source="BID">27774</ref>
      <ref url="http://secunia.com/advisories/28935" source="SECUNIA" adv="1">28935</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="session_initiation_protocol_(sip)_firmware">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="skinny_client_control_protocol_(sccp)_firmware">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0528" published="2008-02-14" name="CVE-2008-0528" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SIP firmware might allow remote attackers to execute arbitrary code via a SIP message with crafted MIME data.</descript>
    </desc>
    <sols>
      <sol source="nvd">Patch requires login</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7a.shtml" source="CISCO" patch="1">20080213 Cisco Unified IP Phone Overflow and Denial of Service Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40492" source="XF">cisco-unifiedipphone-sipmime-bo(40492)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0543" source="VUPEN">ADV-2008-0543</ref>
      <ref url="http://www.securitytracker.com/id?1019409" source="SECTRACK">1019409</ref>
      <ref url="http://www.securityfocus.com/bid/27774" source="BID">27774</ref>
      <ref url="http://secunia.com/advisories/28935" source="SECUNIA" adv="1">28935</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="session_initiation_protocol_(sip)_firmware">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="skinny_client_control_protocol_(sccp)_firmware">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0529" published="2008-02-14" name="CVE-2008-0529" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the telnet server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G running SCCP firmware might allow remote authenticated users to execute arbitrary code via a crafted command.</descript>
    </desc>
    <sols>
      <sol source="nvd">Patch requires login</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7a.shtml" source="CISCO" patch="1">20080213 Cisco Unified IP Phone Overflow and Denial of Service Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40493" source="XF">cisco-unifiedipphone-telnet-bo(40493)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0543" source="VUPEN">ADV-2008-0543</ref>
      <ref url="http://www.securitytracker.com/id?1019410" source="SECTRACK">1019410</ref>
      <ref url="http://www.securityfocus.com/bid/27774" source="BID">27774</ref>
      <ref url="http://secunia.com/advisories/28935" source="SECUNIA" adv="1">28935</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="session_initiation_protocol_(sip)_firmware">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="skinny_client_control_protocol_(sccp)_firmware">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0530" published="2008-02-14" name="CVE-2008-0530" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SCCP and SIP firmware might allow remote attackers to execute arbitrary code via a crafted DNS response.</descript>
    </desc>
    <sols>
      <sol source="nvd">Patch requires login</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7a.shtml" source="CISCO" patch="1">20080213 Cisco Unified IP Phone Overflow and Denial of Service Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40485" source="XF">cisco-unifiedipphone-dns-bo(40485)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0543" source="VUPEN">ADV-2008-0543</ref>
      <ref url="http://www.securityfocus.com/bid/27774" source="BID">27774</ref>
      <ref url="http://secunia.com/advisories/28935" source="SECUNIA" adv="1">28935</ref>
      <ref url="http://www.securitytracker.com/id?1019406" source="SECTRACK">1019406</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="session_initiation_protocol_(sip)_firmware">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="skinny_client_control_protocol_(sccp)_firmware">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0531" published="2008-02-14" name="CVE-2008-0531" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SIP firmware might allow remote SIP servers to execute arbitrary code via a crafted challenge/response message.</descript>
    </desc>
    <sols>
      <sol source="nvd">Patch requires login</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7a.shtml" source="CISCO" patch="1">20080213 Cisco Unified IP Phone Overflow and Denial of Service Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40498" source="XF">cisco-unifiedipphone-sipproxy-bo(40498)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0543" source="VUPEN">ADV-2008-0543</ref>
      <ref url="http://www.securitytracker.com/id?1019411" source="SECTRACK">1019411</ref>
      <ref url="http://www.securityfocus.com/bid/27774" source="BID">27774</ref>
      <ref url="http://secunia.com/advisories/28935" source="SECUNIA" adv="1">28935</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="session_initiation_protocol_(sip)_firmware">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="skinny_client_control_protocol_(sccp)_firmware">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0532" published="2008-03-14" name="CVE-2008-0532" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to execute arbitrary code via a long argument located immediately after the Logout argument, and possibly unspecified other vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/28222" source="BID" patch="1">28222</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a008095f0c4.shtml" source="CISCO" patch="1">20080312 Cisco Secure Access Control Server for Windows User-Changeable Password Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/29351" source="SECUNIA" patch="1" adv="1">29351</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41154" source="XF">cisco-acs-ucp-csusercgi-bo(41154)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0868" source="VUPEN">ADV-2008-0868</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/489463/100/0/threaded" source="BUGTRAQ">20080312 Cisco ACS UCP Remote Pre-Authentication Buffer Overflows</ref>
      <ref url="http://www.recurity-labs.com/content/pub/RecurityLabs_Cisco_ACS_UCP_advisory.txt" source="MISC">http://www.recurity-labs.com/content/pub/RecurityLabs_Cisco_ACS_UCP_advisory.txt</ref>
      <ref url="http://securitytracker.com/id?1019608" source="SECTRACK">1019608</ref>
      <ref url="http://securityreason.com/securityalert/3743" source="SREASON">3743</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="acs_for_windows">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="acs_solution_engine">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="user_changeable_password">
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0533" published="2008-03-14" name="CVE-2008-0533" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to inject arbitrary web script or HTML via an argument located immediately after the Help argument, and possibly unspecified other vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a008095f0c4.shtml" source="CISCO" patch="1">20080312 Cisco Secure Access Control Server for Windows User-Changeable Password Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/29351" source="SECUNIA" patch="1" adv="1">29351</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41156" source="XF">cisco-acs-ucp-csusercgi-xss(41156)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0868" source="VUPEN">ADV-2008-0868</ref>
      <ref url="http://www.securityfocus.com/bid/28222" source="BID">28222</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/489463/100/0/threaded" source="BUGTRAQ">20080312 Cisco ACS UCP Remote Pre-Authentication Buffer Overflows</ref>
      <ref url="http://www.recurity-labs.com/content/pub/RecurityLabs_Cisco_ACS_UCP_advisory.txt" source="MISC">http://www.recurity-labs.com/content/pub/RecurityLabs_Cisco_ACS_UCP_advisory.txt</ref>
      <ref url="http://securitytracker.com/id?1019607" source="SECTRACK">1019607</ref>
      <ref url="http://securityreason.com/securityalert/3743" source="SREASON">3743</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="acs_for_windows">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="acs_solution_engine">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="user_changeable_password">
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0534" published="2008-05-22" name="CVE-2008-0534" modified="2011-06-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The SSH server in (1) Cisco Service Control Engine (SCE) before 3.1.6, and (2) Icon Labs Iconfidant SSH before 2.3.8, allows remote attackers to cause a denial of service (device restart or daemon outage) via a high rate of login attempts, aka Bug ID CSCsi68582.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/626979" source="CERT-VN">VU#626979</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a008099bf65.shtml" source="CISCO" patch="1">20080521 Cisco Service Control Engine Denial of Service Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/42565" source="XF">cisco-sce-sshlogin-dos(42565)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1774/references" source="VUPEN" adv="1">ADV-2008-1774</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1604/references" source="VUPEN" adv="1">ADV-2008-1604</ref>
      <ref url="http://www.securityfocus.com/bid/29609" source="BID">29609</ref>
      <ref url="http://www.securityfocus.com/bid/29316" source="BID">29316</ref>
      <ref url="http://www.icon-labs.com/news/read.asp?newsID=77" source="CONFIRM">http://www.icon-labs.com/news/read.asp?newsID=77</ref>
      <ref url="http://securitytracker.com/id?1020074" source="SECTRACK">1020074</ref>
      <ref url="http://secunia.com/advisories/30590" source="SECUNIA" adv="1">30590</ref>
      <ref url="http://secunia.com/advisories/30316" source="SECUNIA" adv="1">30316</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="service_control_engine">
        <vers prev="1" num="3.1.6"/>
      </prod>
      <prod vendor="icon-labs" name="iconfidant_ssh">
        <vers prev="1" num="2.3.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0535" published="2008-05-22" name="CVE-2008-0535" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the SSH server in (1) Cisco Service Control Engine (SCE) before 3.1.6, and (2) Icon Labs Iconfidant SSH before 2.3.8, allows remote attackers to cause a denial of service (device instability) via "SSH credentials that attempt to change the authentication method," aka Bug ID CSCsm14239.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/626979" source="CERT-VN">VU#626979</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a008099bf65.shtml" source="CISCO" patch="1">20080521 Cisco Service Control Engine Denial of Service Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/42567" source="XF">cisco-sce-ssh-credentials-dos(42567)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1774/references" source="VUPEN" adv="1">ADV-2008-1774</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1604/references" source="VUPEN" adv="1">ADV-2008-1604</ref>
      <ref url="http://www.securityfocus.com/bid/29609" source="BID">29609</ref>
      <ref url="http://www.securityfocus.com/bid/29316" source="BID">29316</ref>
      <ref url="http://www.icon-labs.com/news/read.asp?newsID=77" source="CONFIRM">http://www.icon-labs.com/news/read.asp?newsID=77</ref>
      <ref url="http://securitytracker.com/id?1020074" source="SECTRACK">1020074</ref>
      <ref url="http://secunia.com/advisories/30590" source="SECUNIA" adv="1">30590</ref>
      <ref url="http://secunia.com/advisories/30316" source="SECUNIA" adv="1">30316</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="service_control_engine">
        <vers prev="1" num="3.1.5"/>
      </prod>
      <prod vendor="icon-labs" name="iconfidant_ssh">
        <vers prev="1" num="2.3.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0536" published="2008-05-22" name="CVE-2008-0536" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the SSH server in (1) Cisco Service Control Engine (SCE) 3.0.x before 3.0.7 and 3.1.x before 3.1.0, and (2) Icon Labs Iconfidant SSH before 2.3.8, allows remote attackers to cause a denial of service (management interface outage) via SSH traffic that occurs during management operations and triggers "illegal I/O operations," aka Bug ID CSCsh49563.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/626979" source="CERT-VN">VU#626979</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a008099bf65.shtml" source="CISCO" patch="1">20080521 Cisco Service Control Engine Denial of Service Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/42566" source="XF">cisco-sce-managementagent-dos(42566)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1774/references" source="VUPEN" adv="1">ADV-2008-1774</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1604/references" source="VUPEN" adv="1">ADV-2008-1604</ref>
      <ref url="http://www.securityfocus.com/bid/29609" source="BID">29609</ref>
      <ref url="http://www.securityfocus.com/bid/29316" source="BID">29316</ref>
      <ref url="http://www.icon-labs.com/news/read.asp?newsID=77" source="CONFIRM">http://www.icon-labs.com/news/read.asp?newsID=77</ref>
      <ref url="http://securitytracker.com/id?1020074" source="SECTRACK">1020074</ref>
      <ref url="http://secunia.com/advisories/30590" source="SECUNIA" adv="1">30590</ref>
      <ref url="http://secunia.com/advisories/30316" source="SECUNIA" adv="1">30316</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="service_control_engine">
        <vers num="3.0"/>
        <vers prev="1" num="3.1.6"/>
      </prod>
      <prod vendor="icon-labs" name="iconfidant_ssh">
        <vers prev="1" num="2.3.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0537" published="2008-03-27" name="CVE-2008-0537" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Supervisor Engine 32 (Sup32), Supervisor Engine 720 (Sup720), and Route Switch Processor 720 (RSP720) for multiple Cisco products, when using Multi Protocol Label Switching (MPLS) VPN and OSPF sham-link, allows remote attackers to cause a denial of service (blocked queue, device restart, or memory leak) via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-087B.html" source="CERT">TA08-087B</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/41466" source="XF">cisco-catalyst-sup-rsp-dos(41466)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1005/references" source="VUPEN">ADV-2008-1005</ref>
      <ref url="http://www.securitytracker.com/id?1019716" source="SECTRACK">1019716</ref>
      <ref url="http://www.securityfocus.com/bid/28463" source="BID">28463</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20080326-queue.shtml" source="CISCO" adv="1">20080326 Vulnerability in Cisco IOS with OSPF, MPLS VPN, and Supervisor 32, Supervisor 720, or Route Switch Processor 720</ref>
      <ref url="http://secunia.com/advisories/29559" source="SECUNIA" adv="1">29559</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="route_switch_processor">
        <vers num="rsp720"/>
      </prod>
      <prod vendor="cisco" name="supervisor_engine">
        <vers num="sup32"/>
        <vers num="sup720"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0538" published="2008-02-01" name="CVE-2008-0538" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in phpIP Management 4.3.2 allow remote attackers to execute arbitrary SQL commands via the (1) password parameter to login.php, the (2) id parameter to display.php, and unspecified other vectors.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0346" source="VUPEN">ADV-2008-0346</ref>
      <ref url="http://www.securityfocus.com/bid/27468" source="BID">27468</ref>
      <ref url="http://www.milw0rm.com/exploits/4990" source="MILW0RM">4990</ref>
      <ref url="http://secunia.com/advisories/28656" source="SECUNIA" adv="1">28656</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=120139657100513&amp;w=2" source="FULLDISC">20080127 phpIP 4.3.2 - Numerous SQL Injection Vulnerablities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39965" source="XF">phpip-display-sql-injection(39965)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487122/100/0/threaded" source="BUGTRAQ">20080127 phpIP 4.3.2 - Numerous SQL Injection Vulnerablities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpip" name="phpip_management">
        <vers num="4.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0539" published="2008-02-01" name="CVE-2008-0539" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in dms/policy/rep_request.php in F5 BIG-IP Application Security Manager (ASM) 9.4.3 allows remote attackers to inject arbitrary web script or HTML via the report_type parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0301" source="VUPEN">ADV-2008-0301</ref>
      <ref url="http://www.securityfocus.com/bid/27462" source="BID">27462</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487118/100/0/threaded" source="BUGTRAQ">20080126 F5 BIG-IP Web Management ASM Security Report XSS</ref>
      <ref url="http://secunia.com/advisories/28655" source="SECUNIA">28655</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39979" source="XF">f5bigipwebmgmt-reprequest-xss(39979)</ref>
      <ref url="http://www.securitytracker.com/id?1019276" source="SECTRACK">1019276</ref>
      <ref url="http://www.securityfocus.com/bid/28151" source="BID">28151</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/489290/100/0/threaded" source="BUGTRAQ">20080308 F5 BIG-IP Web Management Console XSS</ref>
      <ref url="http://securityreason.com/securityalert/3602" source="SREASON">3602</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f5" name="big-ip">
        <vers num="9.4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0540" published="2008-02-01" name="CVE-2008-0540" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in trixbox 2.4.2.0 allow remote attackers to inject arbitrary web script or HTML via the query string to index.php in (1) user/ or (2) maint/.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27460" source="BID">27460</ref>
      <ref url="http://www.digitrustgroup.com/advisories/web-application-security-trixbox.html" source="MISC">http://www.digitrustgroup.com/advisories/web-application-security-trixbox.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trixbox" name="trixbox">
        <vers num="2.4.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0541" published="2008-02-01" name="CVE-2008-0541" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in forum.php in Gerd Tentler Simple Forum 3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) open and (2) date_show parameters.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27463" source="BID">27463</ref>
      <ref url="http://www.milw0rm.com/exploits/4989" source="MILW0RM">4989</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39978" source="XF">simpleforum-forum-xss(39978)</ref>
      <ref url="http://secunia.com/advisories/28681" source="SECUNIA">28681</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gerd_tentler" name="simple_forum">
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0542" published="2008-02-01" name="CVE-2008-0542" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in thumbnail.php in Gerd Tentler Simple Forum 3.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39980" source="XF">simpleforum-thumbnail-directory-traversal(39980)</ref>
      <ref url="http://www.securityfocus.com/bid/27463" source="BID">27463</ref>
      <ref url="http://www.milw0rm.com/exploits/4989" source="MILW0RM">4989</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39980" source="XF">simpleforum-thumbnail-file-disclosure(39980)</ref>
      <ref url="http://secunia.com/advisories/28681" source="SECUNIA">28681</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gerd_tentler" name="simple_forum">
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0543" published="2008-02-01" name="CVE-2008-0543" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Pre Dynamic Institution allow remote attackers to execute arbitrary SQL commands via the (1) sloginid and (2) spass parameters to (a) login.asp and (b) siteadmin/login.asp.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39942" source="XF">predynamic-login-sql-injection(39942)</ref>
      <ref url="http://www.securityfocus.com/bid/27451" source="BID">27451</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487054/100/0/threaded" source="BUGTRAQ">20080124 Pre Dynamic Institution bypass</ref>
      <ref url="http://secunia.com/advisories/28651" source="SECUNIA" adv="1">28651</ref>
      <ref url="http://securityreason.com/securityalert/3603" source="SREASON">3603</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pre_projects" name="pre_dynamic_institution">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0544" published="2008-02-01" name="CVE-2008-0544" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the IMG_LoadLBM_RW function in IMG_lbm.c in SDL_image before 1.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted IFF ILBM file.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39899" source="XF">sdlimage-imgloadlbmrw-bo(39899)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0266" source="VUPEN">ADV-2008-0266</ref>
      <ref url="http://www.securityfocus.com/bid/27435" source="BID">27435</ref>
      <ref url="http://www.libsdl.org/cgi/viewvc.cgi/trunk/SDL_image/IMG_lbm.c?revision=3521&amp;view=markup" source="CONFIRM">http://www.libsdl.org/cgi/viewvc.cgi/trunk/SDL_image/IMG_lbm.c?revision=3521&amp;view=markup</ref>
      <ref url="http://www.libsdl.org/cgi/viewvc.cgi/trunk/SDL_image/IMG_lbm.c?r1=3341&amp;r2=3521" source="CONFIRM">http://www.libsdl.org/cgi/viewvc.cgi/trunk/SDL_image/IMG_lbm.c?r1=3341&amp;r2=3521</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1493" source="DEBIAN">DSA-1493</ref>
      <ref url="http://secunia.com/advisories/28640" source="SECUNIA" adv="1">28640</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00039.html" source="FEDORA">FEDORA-2008-1231</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00008.html" source="FEDORA">FEDORA-2008-1208</ref>
      <ref url="https://issues.rpath.com/browse/RPL-2206" source="CONFIRM">https://issues.rpath.com/browse/RPL-2206</ref>
      <ref url="http://www.ubuntu.com/usn/usn-595-1" source="UBUNTU">USN-595-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488079/100/0/threaded" source="BUGTRAQ">20080213 rPSA-2008-0061-1 SDL_image</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:040" source="MANDRIVA">MDVSA-2008:040</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200802-01.xml" source="GENTOO">GLSA-200802-01</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2008-0061" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2008-0061</ref>
      <ref url="http://secunia.com/advisories/29542" source="SECUNIA">29542</ref>
      <ref url="http://secunia.com/advisories/28869" source="SECUNIA">28869</ref>
      <ref url="http://secunia.com/advisories/28850" source="SECUNIA">28850</ref>
      <ref url="http://secunia.com/advisories/28830" source="SECUNIA">28830</ref>
      <ref url="http://secunia.com/advisories/28752" source="SECUNIA">28752</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=207933" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=207933</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sdl" name="sdl_image">
        <vers num="1.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0545" published="2008-02-01" name="CVE-2008-0545" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) uri parameter to (a) yui-menu.tpl.php, (b) simple.tpl.php, and (c) advanced.tpl.php in dispatcher/framework/; and the (2) page parameter to (d) yui-menu.php, (e) simple.php, and (f) advanced.php in dispatcher/framework/, different vectors than CVE-2008-0521.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0347" source="VUPEN">ADV-2008-0347</ref>
      <ref url="http://www.securityfocus.com/bid/27466" source="BID">27466</ref>
      <ref url="http://www.milw0rm.com/exploits/4991" source="MILW0RM">4991</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39969" source="XF">bubblinglibrary-page-uri-file-include(39969)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bubbling_library" name="bubbling_library">
        <vers num="1.32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0546" published="2008-02-01" name="CVE-2008-0546" modified="2009-08-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers to execute arbitrary SQL commands via the (1) idProduct and (2) options parameters to (a) ajax/ajax_optInventory.asp, or the (2) recid parameter to (b) ajax/ajax_getBrands.asp.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39939" source="XF">ecommercesuite-ajaxgetbrands-sql-injection(39939)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0314" source="VUPEN">ADV-2008-0314</ref>
      <ref url="http://www.securityfocus.com/bid/27454" source="BID">27454</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487058/100/0/threaded" source="BUGTRAQ">20080125 [CandyPress] eCommerce suite (SQL Injection + XSS + Path Disclosure)</ref>
      <ref url="http://www.milw0rm.com/exploits/4988" source="MILW0RM">4988</ref>
      <ref url="http://www.candypress.com/CPforum/forum_posts.asp?TID=10630&amp;PN=1" source="CONFIRM">http://www.candypress.com/CPforum/forum_posts.asp?TID=10630&amp;PN=1</ref>
      <ref url="http://secunia.com/advisories/28662" source="SECUNIA" adv="1">28662</ref>
      <ref url="http://securityreason.com/securityalert/3600" source="SREASON">3600</ref>
    </refs>
    <vuln_soft>
      <prod vendor="shoppingtree" name="candypress_store">
        <vers num="4.1"/>
        <vers num="4.1.1.26"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0547" published="2008-02-01" name="CVE-2008-0547" modified="2009-08-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and probably earlier 4.x and 3.x versions, allows remote attackers to inject arbitrary web script or HTML via the helpfield parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39940" source="XF">ecommercesuite-utilitiesconfighelp-xss(39940)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0314" source="VUPEN">ADV-2008-0314</ref>
      <ref url="http://www.securityfocus.com/bid/27454" source="BID">27454</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487058/100/0/threaded" source="BUGTRAQ">20080125 [CandyPress] eCommerce suite (SQL Injection + XSS + Path Disclosure</ref>
      <ref url="http://www.milw0rm.com/exploits/4988" source="MILW0RM">4988</ref>
      <ref url="http://www.candypress.com/CPforum/forum_posts.asp?TID=10630&amp;PN=1" source="CONFIRM">http://www.candypress.com/CPforum/forum_posts.asp?TID=10630&amp;PN=1</ref>
      <ref url="http://secunia.com/advisories/28662" source="SECUNIA" adv="1">28662</ref>
      <ref url="http://securityreason.com/securityalert/3600" source="SREASON">3600</ref>
    </refs>
    <vuln_soft>
      <prod vendor="shoppingtree" name="candypress_store">
        <vers num="4.1"/>
        <vers num="4.1.1.26"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0548" published="2008-02-01" name="CVE-2008-0548" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large integer in the Content-Length HTTP header, which triggers a NULL dereference when malloc fails.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39927" source="XF">steamcast-contentlength-dos(39927)</ref>
      <ref url="http://aluigi.altervista.org/adv/steamcazz-adv.txt" source="MISC">http://aluigi.altervista.org/adv/steamcazz-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="radio_toolbox" name="steamcast">
        <vers prev="1" num="0.9.75"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0549" published="2008-02-01" name="CVE-2008-0549" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in the OggHeaderParse function in Steamcast 0.9.75 and earlier allows remote authenticated users to cause a denial of service (daemon crash) via a long Ogg tag.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39929" source="XF">steamcast-oggheaderparse-dos(39929)</ref>
      <ref url="http://aluigi.org/poc/steamcazz.zip" source="MISC">http://aluigi.org/poc/steamcazz.zip</ref>
      <ref url="http://aluigi.altervista.org/adv/steamcazz-adv.txt" source="MISC">http://aluigi.altervista.org/adv/steamcazz-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="radio_toolbox" name="steamcast">
        <vers prev="1" num="0.9.75"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0550" published="2008-02-01" name="CVE-2008-0550" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Off-by-one error in Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a certain HTTP request that leads to a buffer overflow, as demonstrated by a long User-Agent header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39928" source="XF">steamcast-http-bo(39928)</ref>
      <ref url="http://aluigi.org/poc/steamcazz.zip" source="MISC">http://aluigi.org/poc/steamcazz.zip</ref>
      <ref url="http://aluigi.altervista.org/adv/steamcazz-adv.txt" source="MISC">http://aluigi.altervista.org/adv/steamcazz-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="radio_toolbox" name="steamcast">
        <vers prev="1" num="0.9.75"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2008-0551" published="2008-02-01" name="CVE-2008-0551" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1 and earlier in Namo Web Editor in Sejoong Namo ActiveSquare 6 allows remote attackers to execute arbitrary code via a URL in the argument to the Install method.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0299" source="VUPEN">ADV-2008-0299</ref>
      <ref url="http://www.securityfocus.com/bid/27453" source="BID">27453</ref>
      <ref url="http://www.milw0rm.com/exploits/4986" source="MILW0RM">4986</ref>
      <ref url="http://secunia.com/advisories/28649" source="SECUNIA" adv="1">28649</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39974" source="XF">namoinstaller-namoinstaller-code-execution(39974)</ref>
      <ref url="http://www.securityfocus.com/bid/27580" source="BID">27580</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="activex">
        <vers num=""/>
      </prod>
      <prod vendor="sejoong_namo" name="activesquare">
        <vers num="6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0552" published="2008-02-01" name="CVE-2008-0552" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in eTicket 1.5.6-RC4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39968" source="XF">eticket-index-xss(39968)</ref>
      <ref url="http://www.securitytracker.com/id?1019278" source="SECTRACK">1019278</ref>
      <ref url="http://www.securityfocus.com/bid/27473" source="BID">27473</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487133/100/0/threaded" source="BUGTRAQ">20080127 eTicket 'index.php' Cross Site Scripting Path Vulnerability</ref>
      <ref url="http://www.lonerunners.net/users/jekil/pub/hack-eticket/hack-eticket.txt" source="MISC">http://www.lonerunners.net/users/jekil/pub/hack-eticket/hack-eticket.txt</ref>
      <ref url="http://securityreason.com/securityalert/3601" source="SREASON">3601</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eticket" name="eticket">
        <vers num="1.5.6_rc4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2008-0553" published="2008-02-07" name="CVE-2008-0553" modified="2012-10-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the ReadImage function in tkImgGIF.c in Tk (Tcl/Tk) before 8.5.1 allows remote attackers to execute arbitrary code via a crafted GIF image, a similar issue to CVE-2006-4484.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/27655" source="BID" patch="1">27655</ref>
      <ref url="http://secunia.com/advisories/28784" source="SECUNIA" patch="1" adv="1">28784</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00116.html" source="FEDORA">FEDORA-2008-3545</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00205.html" source="FEDORA">FEDORA-2008-1384</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00193.html" source="FEDORA">FEDORA-2008-1122</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00132.html" source="FEDORA">FEDORA-2008-1131</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00115.html" source="FEDORA">FEDORA-2008-1323</ref>
      <ref url="https://issues.rpath.com/browse/RPL-2215" source="CONFIRM">https://issues.rpath.com/browse/RPL-2215</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=431518" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=431518</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1744" source="VUPEN" adv="1">ADV-2008-1744</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1456/references" source="VUPEN" adv="1">ADV-2008-1456</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0430" source="VUPEN" adv="1">ADV-2008-0430</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2008-0009.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2008-0009.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/493080/100/0/threaded" source="BUGTRAQ">20080604 VMSA-2008-0009 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488069/100/0/threaded" source="BUGTRAQ">20080212 rPSA-2008-0054-1 tk</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0136.html" source="REDHAT">RHSA-2008:0136</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0135.html" source="REDHAT">RHSA-2008:0135</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0134.html" source="REDHAT">RHSA-2008:0134</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2008_13_sr.html" source="SUSE">SUSE-SR:2008:013</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:041" source="MANDRIVA">MDVSA-2008:041</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1598" source="DEBIAN">DSA-1598</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1491" source="DEBIAN">DSA-1491</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1490" source="DEBIAN">DSA-1490</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2008-0054" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2008-0054</ref>
      <ref url="http://ubuntu.com/usn/usn-664-1" source="UBUNTU">USN-664-1</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-237465-1" source="SUNALERT">237465</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=573933&amp;group_id=10894" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=573933&amp;group_id=10894</ref>
      <ref url="http://securitytracker.com/id?1019309" source="SECTRACK">1019309</ref>
      <ref url="http://secunia.com/advisories/32608" source="SECUNIA">32608</ref>
      <ref url="http://secunia.com/advisories/30783" source="SECUNIA" adv="1">30783</ref>
      <ref url="http://secunia.com/advisories/30717" source="SECUNIA" adv="1">30717</ref>
      <ref url="http://secunia.com/advisories/30535" s