<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://nvd.nist.gov/feeds/cve/1.2" nvd_xml_version="1.2" pub_date="2013-06-20" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd">
  <entry type="CVE" severity="High" seq="2009-0001" published="2009-01-21" name="CVE-2009-0001" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted RTSP URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-022A.html" source="CERT">TA09-022A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-01-21</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48154" source="XF">quicktime-rtspurl-bo(48154)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0212" source="VUPEN">ADV-2009-0212</ref>
      <ref url="http://www.securityfocus.com/bid/33385" source="BID">33385</ref>
      <ref url="http://support.apple.com/kb/HT3403" source="CONFIRM">http://support.apple.com/kb/HT3403</ref>
      <ref url="http://secunia.com/advisories/33632" source="SECUNIA">33632</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6135" source="OVAL">oval:org.mitre.oval:def:6135</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.0.8"/>
        <vers num="7.1"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.1.3"/>
        <vers num="7.1.4"/>
        <vers num="7.1.5"/>
        <vers num="7.1.6"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="7.3.1"/>
        <vers num="7.3.1.70"/>
        <vers num="7.4"/>
        <vers num="7.4.1"/>
        <vers num="7.4.4"/>
        <vers num="7.4.5"/>
        <vers num="7.5"/>
        <vers prev="1" num="7.5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0002" published="2009-01-21" name="CVE-2009-0002" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QTVR movie file with crafted THKD atoms.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-022A.html" source="CERT">TA09-022A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-01-21</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-005/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-005/</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0212" source="VUPEN">ADV-2009-0212</ref>
      <ref url="http://www.securityfocus.com/bid/33384" source="BID">33384</ref>
      <ref url="http://support.apple.com/kb/HT3403" source="CONFIRM">http://support.apple.com/kb/HT3403</ref>
      <ref url="http://secunia.com/advisories/33632" source="SECUNIA">33632</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5646" source="OVAL">oval:org.mitre.oval:def:5646</ref>
      <ref url="http://osvdb.org/51525" source="OSVDB">51525</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2009-01/0210.html" source="BUGTRAQ">20090121 ZDI-09-005: Apple QuickTime VR Track Header Atom Heap Corruption Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.0.8"/>
        <vers num="7.1"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.1.3"/>
        <vers num="7.1.4"/>
        <vers num="7.1.5"/>
        <vers num="7.1.6"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="7.3.1"/>
        <vers num="7.3.1.70"/>
        <vers num="7.4"/>
        <vers num="7.4.1"/>
        <vers num="7.4.4"/>
        <vers num="7.4.5"/>
        <vers num="7.5"/>
        <vers prev="1" num="7.5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0003" published="2009-01-21" name="CVE-2009-0003" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via an AVI movie file with an invalid nBlockAlign value in the _WAVEFORMATEX structure.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-022A.html" source="CERT">TA09-022A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-01-21</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-006/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-006/</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0212" source="VUPEN" adv="1">ADV-2009-0212</ref>
      <ref url="http://www.securityfocus.com/bid/33387" source="BID">33387</ref>
      <ref url="http://support.apple.com/kb/HT3403" source="CONFIRM">http://support.apple.com/kb/HT3403</ref>
      <ref url="http://secunia.com/advisories/33632" source="SECUNIA" adv="1">33632</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6218" source="OVAL">oval:org.mitre.oval:def:6218</ref>
      <ref url="http://osvdb.org/51526" source="OSVDB">51526</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.0.8"/>
        <vers num="7.1"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.1.3"/>
        <vers num="7.1.4"/>
        <vers num="7.1.5"/>
        <vers num="7.1.6"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="7.3.1"/>
        <vers num="7.3.1.70"/>
        <vers num="7.4"/>
        <vers num="7.4.1"/>
        <vers num="7.4.4"/>
        <vers num="7.4.5"/>
        <vers num="7.5"/>
        <vers prev="1" num="7.5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0004" published="2009-01-21" name="CVE-2009-0004" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted MP3 audio file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-022A.html" source="CERT" patch="1">TA09-022A</ref>
      <ref url="http://support.apple.com/kb/HT3403" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3403</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-01-21</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48157" source="XF">quicktime-mpeg2-bo(48157)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0212" source="VUPEN">ADV-2009-0212</ref>
      <ref url="http://secunia.com/advisories/33632" source="SECUNIA" adv="1">33632</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6211" source="OVAL">oval:org.mitre.oval:def:6211</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.0.8"/>
        <vers num="7.1"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.1.3"/>
        <vers num="7.1.4"/>
        <vers num="7.1.5"/>
        <vers num="7.1.6"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="7.3.1"/>
        <vers num="7.3.1.70"/>
        <vers num="7.4"/>
        <vers num="7.4.1"/>
        <vers num="7.4.4"/>
        <vers num="7.4.5"/>
        <vers num="7.5"/>
        <vers prev="1" num="7.5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0005" published="2009-01-21" name="CVE-2009-0005" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted H.263 encoded movie file that triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-022A.html" source="CERT">TA09-022A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-01-21</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48158" source="XF">quicktime-h263-movie-code-execution(48158)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0212" source="VUPEN">ADV-2009-0212</ref>
      <ref url="http://www.securityfocus.com/bid/33386" source="BID">33386</ref>
      <ref url="http://support.apple.com/kb/HT3403" source="CONFIRM">http://support.apple.com/kb/HT3403</ref>
      <ref url="http://secunia.com/advisories/33632" source="SECUNIA">33632</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6187" source="OVAL">oval:org.mitre.oval:def:6187</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.0.8"/>
        <vers num="7.1"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.1.3"/>
        <vers num="7.1.4"/>
        <vers num="7.1.5"/>
        <vers num="7.1.6"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="7.3.1"/>
        <vers num="7.3.1.70"/>
        <vers num="7.4"/>
        <vers num="7.4.1"/>
        <vers num="7.4.4"/>
        <vers num="7.4.5"/>
        <vers num="7.5"/>
        <vers prev="1" num="7.5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0006" published="2009-01-21" name="CVE-2009-0006" modified="2012-02-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer signedness error in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a Cinepak encoded movie file with a crafted MDAT atom that triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-022A.html" source="CERT">TA09-022A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-01-21</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-007/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-007/</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0212" source="VUPEN" adv="1">ADV-2009-0212</ref>
      <ref url="http://www.securityfocus.com/bid/33388" source="BID">33388</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500391/100/0/threaded" source="BUGTRAQ">20090124 Re: ZDI-09-007: Apple QuickTime Cinepak Codec MDAT Heap Corruption Vulnerability</ref>
      <ref url="http://support.apple.com/kb/HT3403" source="CONFIRM">http://support.apple.com/kb/HT3403</ref>
      <ref url="http://secunia.com/advisories/33632" source="SECUNIA" adv="1">33632</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6153" source="OVAL">oval:org.mitre.oval:def:6153</ref>
      <ref url="http://osvdb.org/51529" source="OSVDB">51529</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2009-01/0215.html" source="BUGTRAQ">20090121 ZDI-09-007: Apple QuickTime Cinepak Codec MDAT Heap Corruption Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3.0"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.1"/>
        <vers num="6.1.0"/>
        <vers num="6.1.1"/>
        <vers num="6.2.0"/>
        <vers num="6.3.0"/>
        <vers num="6.4.0"/>
        <vers num="6.5"/>
        <vers num="6.5.0"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="7.0"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.1"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.1.3"/>
        <vers num="7.1.4"/>
        <vers num="7.1.5"/>
        <vers num="7.1.6"/>
        <vers num="7.2"/>
        <vers num="7.2.1"/>
        <vers num="7.3"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.1.70"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.5"/>
        <vers num="7.5.0"/>
        <vers prev="1" num="7.5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0007" published="2009-01-21" name="CVE-2009-0007" modified="2012-02-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QuickTime movie file containing invalid image width data in JPEG atoms within STSD atoms.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-022A.html" source="CERT">TA09-022A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-01-21</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-008/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-008/</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0212" source="VUPEN" adv="1">ADV-2009-0212</ref>
      <ref url="http://www.securityfocus.com/bid/33390" source="BID">33390</ref>
      <ref url="http://support.apple.com/kb/HT3403" source="CONFIRM" adv="1">http://support.apple.com/kb/HT3403</ref>
      <ref url="http://secunia.com/advisories/33632" source="SECUNIA" adv="1">33632</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6132" source="OVAL">oval:org.mitre.oval:def:6132</ref>
      <ref url="http://osvdb.org/51530" source="OSVDB">51530</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3.0"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.1"/>
        <vers num="6.1.0"/>
        <vers num="6.1.1"/>
        <vers num="6.2.0"/>
        <vers num="6.3.0"/>
        <vers num="6.4.0"/>
        <vers num="6.5"/>
        <vers num="6.5.0"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="7.0"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.1"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.1.3"/>
        <vers num="7.1.4"/>
        <vers num="7.1.5"/>
        <vers num="7.1.6"/>
        <vers num="7.2"/>
        <vers num="7.2.1"/>
        <vers num="7.3"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.1.70"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.5"/>
        <vers num="7.5.0"/>
        <vers prev="1" num="7.5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0008" published="2009-01-22" name="CVE-2009-0008" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in Apple QuickTime MPEG-2 Playback Component before 7.60.92.0 on Windows allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted MPEG-2 movie.</descript>
      <descript source="nvd">per http://lists.apple.com/archives/security-announce//2009/Jan/msg00001.html

"This issue does not
affect systems running Mac OS X."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48162" source="XF">quicktime-mpeg2playback-code-execution(48162)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0211" source="VUPEN">ADV-2009-0211</ref>
      <ref url="http://www.securitytracker.com/id?1021621" source="SECTRACK">1021621</ref>
      <ref url="http://www.securityfocus.com/bid/33393" source="BID">33393</ref>
      <ref url="http://support.apple.com/kb/HT3404" source="CONFIRM" adv="1">http://support.apple.com/kb/HT3404</ref>
      <ref url="http://secunia.com/advisories/33642" source="SECUNIA" adv="1">33642</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5974" source="OVAL">oval:org.mitre.oval:def:5974</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2009/Jan/msg00001.html" source="APPLE" adv="1">APPLE-SA-2009-01-21</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime_mpeg-2_playback_component">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0009" published="2009-02-12" name="CVE-2009-0009" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Pixlet codec in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted movie file that triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48713" source="XF">macosx-pixlet-codec-code-execution(48713)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://www.securityfocus.com/bid/33759" source="BID">33759</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://securitytracker.com/alerts/2009/Feb/1021718.html" source="SECTRACK">1021718</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA">33937</ref>
      <ref url="http://osvdb.org/51980" source="OSVDB">51980</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE">APPLE-SA-2009-02-12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0010" published="2009-05-13" name="CVE-2009-0010" modified="2009-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer underflow in QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7, and Apple QuickTime before 7.6.2, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PICT image with a crafted 0x77 Poly tag and a crafted length field, which triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-021/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-021/</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-021" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-021</ref>
      <ref url="http://www.vupen.com/exploits/Apple_QuickTime_PICT_Poly_Tag_Parsing_Heap_Overflow_PoC_Exploit_1407144.php" source="MISC">http://www.vupen.com/exploits/Apple_QuickTime_PICT_Poly_Tag_Parsing_Heap_Overflow_PoC_Exploit_1407144.php</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1407" source="VUPEN">ADV-2009-1407</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securitytracker.com/id?1022209" source="SECTRACK">1022209</ref>
      <ref url="http://www.securityfocus.com/bid/34938" source="BID">34938</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503878/100/0/threaded" source="BUGTRAQ">20090527 ZDI-09-021: Apple QuickTime PICT Unspecified Tag Heap Overflow Vulnerability</ref>
      <ref url="http://support.apple.com/kb/HT3591" source="CONFIRM">http://support.apple.com/kb/HT3591</ref>
      <ref url="http://secunia.com/advisories/35091" source="SECUNIA">35091</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00000.html" source="APPLE">APPLE-SA-2009-06-01-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
        <vers num="10.5"/>
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0011" published="2009-02-12" name="CVE-2009-0011" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Certificate Assistant in Apple Mac OS X 10.5.6 allows local users to overwrite arbitrary files via unknown vectors related to an "insecure file operation" on a temporary file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33759" source="BID" patch="1">33759</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-02-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48715" source="XF">macosx-certificate-asst-file-overwrite(48715)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://securitytracker.com/alerts/2009/Feb/1021720.html" source="SECTRACK">1021720</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA" adv="1">33937</ref>
      <ref url="http://osvdb.org/51979" source="OSVDB">51979</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0012" published="2009-02-12" name="CVE-2009-0012" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in CoreText in Apple Mac OS X 10.5.6 allows remote attackers to execute arbitrary code via a crafted Unicode string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-02-12</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN" adv="1">ADV-2009-0422</ref>
      <ref url="http://www.securityfocus.com/bid/33809" source="BID">33809</ref>
      <ref url="http://www.securityfocus.com/bid/33759" source="BID">33759</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA" adv="1">33937</ref>
      <ref url="http://osvdb.org/51977" source="OSVDB">51977</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0013" published="2009-02-12" name="CVE-2009-0013" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">dscl in DS Tools in Apple Mac OS X 10.4.11 and 10.5.6 requires that passwords must be provided as command line arguments, which allows local users to gain privileges by listing process information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-02-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48717" source="XF">macosx-dstools-information-disclosure(48717)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://www.securityfocus.com/bid/33815" source="BID">33815</ref>
      <ref url="http://www.securityfocus.com/bid/33759" source="BID">33759</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://securitytracker.com/alerts/2009/Feb/1021722.html" source="SECTRACK">1021722</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA">33937</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0014" published="2009-02-12" name="CVE-2009-0014" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Folder Manager in Apple Mac OS X 10.5.6 uses insecure default permissions when recreating a Downloads folder after it has been deleted, which allows local users to bypass intended access restrictions and read the Downloads folder.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-02-12</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://www.securityfocus.com/bid/33820" source="BID">33820</ref>
      <ref url="http://www.securityfocus.com/bid/33759" source="BID">33759</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA">33937</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0015" published="2009-02-12" name="CVE-2009-0015" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in fseventsd in the FSEvents framework in Apple Mac OS X 10.5.6 allows local users to obtain sensitive information (filesystem activities and directory names) via unknown vectors related to "credential management."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-02-12</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://www.securityfocus.com/bid/33821" source="BID">33821</ref>
      <ref url="http://www.securityfocus.com/bid/33759" source="BID">33759</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA">33937</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0016" published="2009-03-14" name="CVE-2009-0016" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apple iTunes before 8.1 on Windows allows remote attackers to cause a denial of service (infinite loop) via a Digital Audio Access Protocol (DAAP) message with a crafted Content-Length header.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT3487" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3487</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2009/Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-03-11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49200" source="XF">itunes-daap-dos(49200)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0702" source="VUPEN">ADV-2009-0702</ref>
      <ref url="http://www.securityfocus.com/bid/34094" source="BID">34094</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501758/100/0/threaded" source="BUGTRAQ">20090313 Apple iTunes DAAP Messages Handling Denial of Service Vulnerability</ref>
      <ref url="http://www.fortiguardcenter.com/advisory/FGA-2009-11.html" source="MISC">http://www.fortiguardcenter.com/advisory/FGA-2009-11.html</ref>
      <ref url="http://securitytracker.com/id?1021842" source="SECTRACK">1021842</ref>
      <ref url="http://secunia.com/advisories/34254" source="SECUNIA" adv="1">34254</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6001" source="OVAL">oval:org.mitre.oval:def:6001</ref>
      <ref url="http://osvdb.org/52578" source="OSVDB">52578</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-03/0236.html" source="FULLDISC">20090312 Apple iTunes DAAP Messages Handling Denial of Service Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="1.0" edition=""/>
        <vers num="1.0" edition=":windows"/>
        <vers num="1.1.1" edition=""/>
        <vers num="1.1.1" edition=":windows"/>
        <vers num="1.1.2" edition=""/>
        <vers num="1.1.2" edition=":windows"/>
        <vers num="2.0" edition=""/>
        <vers num="2.0" edition=":windows"/>
        <vers num="2.0.1" edition=""/>
        <vers num="2.0.1" edition=":windows"/>
        <vers num="2.0.2" edition=""/>
        <vers num="2.0.2" edition=":windows"/>
        <vers num="2.0.3" edition=""/>
        <vers num="2.0.3" edition=":windows"/>
        <vers num="2.0.4" edition=""/>
        <vers num="2.0.4" edition=":windows"/>
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":windows"/>
        <vers num="3.0.1" edition=""/>
        <vers num="3.0.1" edition=":windows"/>
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":windows"/>
        <vers num="4.0.0" edition="-"/>
        <vers num="4.0.0" edition="-:windows"/>
        <vers num="4.0.1" edition=""/>
        <vers num="4.0.1" edition=":windows"/>
        <vers num="4.0.1" edition="-"/>
        <vers num="4.0.1" edition="-:windows"/>
        <vers num="4.1" edition=""/>
        <vers num="4.1" edition=":windows"/>
        <vers num="4.1.0" edition="-"/>
        <vers num="4.1.0" edition="-:windows"/>
        <vers num="4.2" edition=""/>
        <vers num="4.2" edition=":windows"/>
        <vers num="4.2.0" edition="-"/>
        <vers num="4.2.0" edition="-:windows"/>
        <vers num="4.2.72" edition=""/>
        <vers num="4.2.72" edition=":windows"/>
        <vers num="4.5" edition=""/>
        <vers num="4.5" edition=":windows"/>
        <vers num="4.5.0" edition="-"/>
        <vers num="4.5.0" edition="-:windows"/>
        <vers num="4.6" edition=""/>
        <vers num="4.6" edition=":windows"/>
        <vers num="4.6.0" edition="-"/>
        <vers num="4.6.0" edition="-:windows"/>
        <vers num="4.7" edition=""/>
        <vers num="4.7" edition=":windows"/>
        <vers num="4.7.0" edition="-"/>
        <vers num="4.7.0" edition="-:windows"/>
        <vers num="4.7.1" edition=""/>
        <vers num="4.7.1" edition=":windows"/>
        <vers num="4.7.1" edition="-"/>
        <vers num="4.7.1" edition="-:windows"/>
        <vers num="4.7.1.30" edition=""/>
        <vers num="4.7.1.30" edition=":windows"/>
        <vers num="4.8" edition=""/>
        <vers num="4.8" edition=":windows"/>
        <vers num="4.8.0" edition="-"/>
        <vers num="4.8.0" edition="-:windows"/>
        <vers num="4.9" edition=""/>
        <vers num="4.9" edition=":windows"/>
        <vers num="4.9.0" edition="-"/>
        <vers num="4.9.0" edition="-:windows"/>
        <vers num="5.0" edition=""/>
        <vers num="5.0" edition=":windows"/>
        <vers num="5.0.0" edition="-"/>
        <vers num="5.0.0" edition="-:windows"/>
        <vers num="5.0.1" edition=""/>
        <vers num="5.0.1" edition=":windows"/>
        <vers num="5.0.1" edition="-"/>
        <vers num="5.0.1" edition="-:windows"/>
        <vers num="6.0" edition=""/>
        <vers num="6.0" edition=":windows"/>
        <vers num="6.0.0" edition="-"/>
        <vers num="6.0.0" edition="-:windows"/>
        <vers num="6.0.1" edition=""/>
        <vers num="6.0.1" edition=":windows"/>
        <vers num="6.0.1" edition="-"/>
        <vers num="6.0.1" edition="-:windows"/>
        <vers num="6.0.2" edition=""/>
        <vers num="6.0.2" edition=":windows"/>
        <vers num="6.0.2" edition="-"/>
        <vers num="6.0.2" edition="-:windows"/>
        <vers num="6.0.3" edition=""/>
        <vers num="6.0.3" edition=":windows"/>
        <vers num="6.0.3" edition="-"/>
        <vers num="6.0.3" edition="-:windows"/>
        <vers num="6.0.4" edition=""/>
        <vers num="6.0.4" edition=":windows"/>
        <vers num="6.0.4" edition="-"/>
        <vers num="6.0.4" edition="-:windows"/>
        <vers num="6.0.4.2" edition=""/>
        <vers num="6.0.4.2" edition=":windows"/>
        <vers num="6.0.5" edition=""/>
        <vers num="6.0.5" edition=":windows"/>
        <vers num="6.0.5" edition="-"/>
        <vers num="6.0.5" edition="-:windows"/>
        <vers num="7.0.0" edition="-"/>
        <vers num="7.0.0" edition="-:windows"/>
        <vers num="7.0.1" edition="-"/>
        <vers num="7.0.1" edition="-:windows"/>
        <vers num="7.0.2" edition=""/>
        <vers num="7.0.2" edition=":windows"/>
        <vers num="7.0.2" edition="-"/>
        <vers num="7.0.2" edition="-:windows"/>
        <vers num="7.1.0" edition="-"/>
        <vers num="7.1.0" edition="-:windows"/>
        <vers num="7.1.1" edition="-"/>
        <vers num="7.1.1" edition="-:windows"/>
        <vers num="7.2.0" edition="-"/>
        <vers num="7.2.0" edition="-:windows"/>
        <vers num="7.3.0" edition="-"/>
        <vers num="7.3.0" edition="-:windows"/>
        <vers num="7.3.1" edition="-"/>
        <vers num="7.3.1" edition="-:windows"/>
        <vers num="7.3.2" edition=""/>
        <vers num="7.3.2" edition=":windows"/>
        <vers num="7.3.2" edition="-"/>
        <vers num="7.3.2" edition="-:windows"/>
        <vers num="7.4" edition=""/>
        <vers num="7.4" edition=":windows"/>
        <vers num="7.4.0" edition="-"/>
        <vers num="7.4.0" edition="-:windows"/>
        <vers num="7.4.1" edition=""/>
        <vers num="7.4.1" edition=":windows"/>
        <vers num="7.4.1" edition="-"/>
        <vers num="7.4.1" edition="-:windows"/>
        <vers num="7.4.2" edition=""/>
        <vers num="7.4.2" edition=":windows"/>
        <vers num="7.4.2" edition="-"/>
        <vers num="7.4.2" edition="-:windows"/>
        <vers num="7.4.3" edition=""/>
        <vers num="7.4.3" edition=":windows"/>
        <vers num="7.5" edition=""/>
        <vers num="7.5" edition=":windows"/>
        <vers num="7.5.0" edition="-"/>
        <vers num="7.5.0" edition="-:windows"/>
        <vers num="7.6" edition=""/>
        <vers num="7.6" edition=":windows"/>
        <vers num="7.6.0" edition="-"/>
        <vers num="7.6.0" edition="-:windows"/>
        <vers num="7.6.1" edition=""/>
        <vers num="7.6.1" edition=":windows"/>
        <vers num="7.6.1" edition="-"/>
        <vers num="7.6.1" edition="-:windows"/>
        <vers num="7.6.2" edition="-"/>
        <vers num="7.6.2" edition="-:windows"/>
        <vers num="7.7" edition=""/>
        <vers num="7.7" edition=":windows"/>
        <vers num="7.7.0" edition="-"/>
        <vers num="7.7.0" edition="-:windows"/>
        <vers num="7.7.1" edition=""/>
        <vers num="7.7.1" edition=":windows"/>
        <vers num="7.7.1" edition="-"/>
        <vers num="7.7.1" edition="-:windows"/>
        <vers prev="1" num="8.0" edition=""/>
        <vers prev="1" num="8.0" edition=":windows"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0017" published="2009-02-12" name="CVE-2009-0017" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">csregprinter in the Printing component in Apple Mac OS X 10.4.11 and 10.5.6 does not properly handle error conditions, which allows local users to execute arbitrary code via unknown vectors that trigger a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-02-12</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://www.securityfocus.com/bid/33811" source="BID">33811</ref>
      <ref url="http://www.securityfocus.com/bid/33759" source="BID">33759</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA">33937</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0018" published="2009-02-12" name="CVE-2009-0018" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The Remote Apple Events server in Apple Mac OS X 10.4.11 and 10.5.6 does not properly initialize a buffer, which allows remote attackers to read portions of memory.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://www.securityfocus.com/bid/33816" source="BID">33816</ref>
      <ref url="http://www.securityfocus.com/bid/33759" source="BID">33759</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA">33937</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE">APPLE-SA-2009-02-12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0019" published="2009-02-12" name="CVE-2009-0019" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Remote Apple Events in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application termination) or obtain sensitive information via unspecified vectors that trigger an out-of-bounds memory access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://www.securityfocus.com/bid/33814" source="BID">33814</ref>
      <ref url="http://www.securityfocus.com/bid/33759" source="BID">33759</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE" adv="1">APPLE-SA-2009-02-12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0020" published="2009-02-12" name="CVE-2009-0020" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted resource fork that triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-02-12</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://www.securityfocus.com/bid/33759" source="BID">33759</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA">33937</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0021" published="2009-01-07" name="CVE-2009-0021" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.</descript>
      <descript source="nvd">Note that versions 4.2.5 before 4.2.5p150 are development versions and not production versions.  Development versions are not included in the CPE configuration for CVEs.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="https://lists.ntp.org/pipermail/announce/2009-January/000055.html" source="MLIST">[announce] 20090108 NTP 4.2.4p6 Released</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN" adv="1">ADV-2009-1297</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0042" source="VUPEN" adv="1">ADV-2009-0042</ref>
      <ref url="http://www.securitytracker.com/id?1021533" source="SECTRACK">1021533</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/499827/100/0/threaded" source="BUGTRAQ">20090107 [oCERT-2008-016] Multiple OpenSSL signature verification API misuses</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0046.html" source="REDHAT">RHSA-2009:0046</ref>
      <ref url="http://www.ocert.org/advisories/ocert-2008-016.html" source="MISC">http://www.ocert.org/advisories/ocert-2008-016.html</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.531177" source="SLACKWARE">SSA:2009-014-03</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA" adv="1">35074</ref>
      <ref url="http://secunia.com/advisories/34642" source="SECUNIA" adv="1">34642</ref>
      <ref url="http://secunia.com/advisories/33648" source="SECUNIA" adv="1">33648</ref>
      <ref url="http://secunia.com/advisories/33558" source="SECUNIA" adv="1">33558</ref>
      <ref url="http://secunia.com/advisories/33406" source="SECUNIA" adv="1">33406</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10035" source="OVAL">oval:org.mitre.oval:def:10035</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.html" source="SUSE">SUSE-SR:2009:008</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html" source="SUSE">SUSE-SR:2009:005</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ntp" name="ntp">
        <vers num="4.2.0"/>
        <vers num="4.2.2"/>
        <vers num="4.2.4p1"/>
        <vers num="4.2.4p2"/>
        <vers num="4.2.4p3"/>
        <vers prev="1" num="4.2.4p4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0022" published="2009-01-05" name="CVE-2009-0022" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:N/A:N)" CVSS_score="6.3" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.8" CVSS_base_score="6.3">
    <desc>
      <descript source="cve">Samba 3.2.0 through 3.2.6, when registry shares are enabled, allows remote authenticated users to access the root filesystem via a crafted connection request that specifies a blank share name.</descript>
    </desc>
    <sols>
      <sol source="nvd">Patch Information - http://www.samba.org/samba/history/security.html</sol>
    </sols>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00309.html" source="FEDORA">FEDORA-2009-0268</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/47733" source="XF">samba-file-system-security-bypass(47733)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0017" source="VUPEN">ADV-2009-0017</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-702-1" source="UBUNTU">USN-702-1</ref>
      <ref url="http://www.securitytracker.com/id?1021513" source="SECTRACK">1021513</ref>
      <ref url="http://www.securityfocus.com/bid/33118" source="BID">33118</ref>
      <ref url="http://www.samba.org/samba/security/CVE-2009-0022.html" source="CONFIRM">http://www.samba.org/samba/security/CVE-2009-0022.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:042" source="MANDRIVA">MDVSA-2009:042</ref>
      <ref url="http://secunia.com/advisories/33431" source="SECUNIA">33431</ref>
      <ref url="http://secunia.com/advisories/33392" source="SECUNIA">33392</ref>
      <ref url="http://secunia.com/advisories/33379" source="SECUNIA" adv="1">33379</ref>
      <ref url="http://osvdb.org/51152" source="OSVDB">51152</ref>
      <ref url="http://master.samba.org/samba/ftp/patches/security/samba-3.2.6-CVE-2009-0022.patch" source="MISC">http://master.samba.org/samba/ftp/patches/security/samba-3.2.6-CVE-2009-0022.patch</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0023" published="2009-06-07" name="CVE-2009-0023" modified="2013-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=503928" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=503928</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1812" source="DEBIAN" patch="1">DSA-1812</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01228.html" source="FEDORA">FEDORA-2009-5969</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01201.html" source="FEDORA">FEDORA-2009-6261</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01173.html" source="FEDORA">FEDORA-2009-6014</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50964" source="XF">apache-aprstrmatchprecompile-dos(50964)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3184" source="VUPEN">ADV-2009-3184</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1907" source="VUPEN">ADV-2009-1907</ref>
      <ref url="http://www.ubuntu.com/usn/usn-787-1" source="UBUNTU">USN-787-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-786-1" source="UBUNTU">USN-786-1</ref>
      <ref url="http://www.securityfocus.com/bid/35221" source="BID">35221</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507855/100/0/threaded" source="BUGTRAQ">20091112 rPSA-2009-0144-1 apr-util</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1108.html" source="REDHAT">RHSA-2009:1108</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1107.html" source="REDHAT">RHSA-2009:1107</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:131" source="MANDRIVA">MDVSA-2009:131</ref>
      <ref url="http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3" source="CONFIRM">http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27014463" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27014463</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PK99478" source="AIXAPAR">PK99478</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PK91241" source="AIXAPAR">PK91241</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PK88341" source="AIXAPAR">PK88341</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0144" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0144</ref>
      <ref url="http://svn.apache.org/viewvc?view=rev&amp;revision=779880" source="CONFIRM">http://svn.apache.org/viewvc?view=rev&amp;revision=779880</ref>
      <ref url="http://support.apple.com/kb/HT3937" source="CONFIRM">http://support.apple.com/kb/HT3937</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.538210" source="SLACKWARE">SSA:2009-167-02</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-03.xml" source="GENTOO">GLSA-200907-03</ref>
      <ref url="http://secunia.com/advisories/37221" source="SECUNIA">37221</ref>
      <ref url="http://secunia.com/advisories/35843" source="SECUNIA">35843</ref>
      <ref url="http://secunia.com/advisories/35797" source="SECUNIA">35797</ref>
      <ref url="http://secunia.com/advisories/35710" source="SECUNIA">35710</ref>
      <ref url="http://secunia.com/advisories/35565" source="SECUNIA">35565</ref>
      <ref url="http://secunia.com/advisories/35487" source="SECUNIA">35487</ref>
      <ref url="http://secunia.com/advisories/35444" source="SECUNIA">35444</ref>
      <ref url="http://secunia.com/advisories/35395" source="SECUNIA">35395</ref>
      <ref url="http://secunia.com/advisories/35360" source="SECUNIA" adv="1">35360</ref>
      <ref url="http://secunia.com/advisories/35284" source="SECUNIA" adv="1">35284</ref>
      <ref url="http://secunia.com/advisories/34724" source="SECUNIA">34724</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12321" source="OVAL">oval:org.mitre.oval:def:12321</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10968" source="OVAL">oval:org.mitre.oval:def:10968</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129190899612998&amp;w=2" source="HP">HPSBUX02612</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129190899612998&amp;w=2" source="HP">HPSBUX02612</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html" source="APPLE">APPLE-SA-2009-11-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="apr-util">
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="0.9.5"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.2.8"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers prev="1" num="1.3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0024" published="2009-01-13" name="CVE-2009-0024" modified="2012-03-19" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The sys_remap_file_pages function in mm/fremap.c in the Linux kernel before 2.6.24.1 allows local users to cause a denial of service or gain privileges via unspecified vectors, related to the vm_file structure member, and the mmap_region and do_munmap functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33211" source="BID" patch="1">33211</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/01/12/1" source="MLIST">[oss-security] 20090112 CVE-2009-0024 kernel: local privilege escalation in sys_remap_file_pages</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.24.y.git;a=commit;h=8a459e44ad837018ea5c34a9efe8eb4ad27ded26" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.24.y.git;a=commit;h=8a459e44ad837018ea5c34a9efe8eb4ad27ded26</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.2.27"/>
        <vers num="2.4.36"/>
        <vers num="2.4.36.1"/>
        <vers num="2.4.36.2"/>
        <vers num="2.4.36.3"/>
        <vers num="2.4.36.4"/>
        <vers num="2.4.36.5"/>
        <vers num="2.4.36.6"/>
        <vers num="2.6"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.10"/>
        <vers num="2.6.11"/>
        <vers num="2.6.11.1"/>
        <vers num="2.6.11.10"/>
        <vers num="2.6.11.11"/>
        <vers num="2.6.11.12"/>
        <vers num="2.6.11.2"/>
        <vers num="2.6.11.3"/>
        <vers num="2.6.11.4"/>
        <vers num="2.6.11.5"/>
        <vers num="2.6.11.6"/>
        <vers num="2.6.11.7"/>
        <vers num="2.6.11.8"/>
        <vers num="2.6.11.9"/>
        <vers num="2.6.12"/>
        <vers num="2.6.12.1"/>
        <vers num="2.6.12.2"/>
        <vers num="2.6.12.3"/>
        <vers num="2.6.12.4"/>
        <vers num="2.6.12.5"/>
        <vers num="2.6.12.6"/>
        <vers num="2.6.13"/>
        <vers num="2.6.13.1"/>
        <vers num="2.6.13.2"/>
        <vers num="2.6.13.3"/>
        <vers num="2.6.13.4"/>
        <vers num="2.6.13.5"/>
        <vers num="2.6.14"/>
        <vers num="2.6.14.1"/>
        <vers num="2.6.14.2"/>
        <vers num="2.6.14.3"/>
        <vers num="2.6.14.4"/>
        <vers num="2.6.14.5"/>
        <vers num="2.6.14.6"/>
        <vers num="2.6.14.7"/>
        <vers num="2.6.15"/>
        <vers num="2.6.15.1"/>
        <vers num="2.6.15.2"/>
        <vers num="2.6.15.3"/>
        <vers num="2.6.15.4"/>
        <vers num="2.6.15.5"/>
        <vers num="2.6.15.6"/>
        <vers num="2.6.15.7"/>
        <vers num="2.6.16"/>
        <vers num="2.6.16.1"/>
        <vers num="2.6.16.10"/>
        <vers num="2.6.16.11"/>
        <vers num="2.6.16.12"/>
        <vers num="2.6.16.13"/>
        <vers num="2.6.16.14"/>
        <vers num="2.6.16.15"/>
        <vers num="2.6.16.16"/>
        <vers num="2.6.16.17"/>
        <vers num="2.6.16.18"/>
        <vers num="2.6.16.19"/>
        <vers num="2.6.16.2"/>
        <vers num="2.6.16.20"/>
        <vers num="2.6.16.21"/>
        <vers num="2.6.16.22"/>
        <vers num="2.6.16.23"/>
        <vers num="2.6.16.24"/>
        <vers num="2.6.16.25"/>
        <vers num="2.6.16.26"/>
        <vers num="2.6.16.27"/>
        <vers num="2.6.16.28"/>
        <vers num="2.6.16.29"/>
        <vers num="2.6.16.3"/>
        <vers num="2.6.16.30"/>
        <vers num="2.6.16.31"/>
        <vers num="2.6.16.32"/>
        <vers num="2.6.16.33"/>
        <vers num="2.6.16.34"/>
        <vers num="2.6.16.35"/>
        <vers num="2.6.16.36"/>
        <vers num="2.6.16.37"/>
        <vers num="2.6.16.38"/>
        <vers num="2.6.16.39"/>
        <vers num="2.6.16.4"/>
        <vers num="2.6.16.40"/>
        <vers num="2.6.16.41"/>
        <vers num="2.6.16.42"/>
        <vers num="2.6.16.43"/>
        <vers num="2.6.16.44"/>
        <vers num="2.6.16.45"/>
        <vers num="2.6.16.46"/>
        <vers num="2.6.16.47"/>
        <vers num="2.6.16.48"/>
        <vers num="2.6.16.49"/>
        <vers num="2.6.16.5"/>
        <vers num="2.6.16.50"/>
        <vers num="2.6.16.51"/>
        <vers num="2.6.16.52"/>
        <vers num="2.6.16.53"/>
        <vers num="2.6.16.54"/>
        <vers num="2.6.16.55"/>
        <vers num="2.6.16.56"/>
        <vers num="2.6.16.57"/>
        <vers num="2.6.16.58"/>
        <vers num="2.6.16.59"/>
        <vers num="2.6.16.6"/>
        <vers num="2.6.16.60"/>
        <vers num="2.6.16.61"/>
        <vers num="2.6.16.62"/>
        <vers num="2.6.16.7"/>
        <vers num="2.6.16.8"/>
        <vers num="2.6.16.9"/>
        <vers num="2.6.17"/>
        <vers num="2.6.17.1"/>
        <vers num="2.6.17.10"/>
        <vers num="2.6.17.11"/>
        <vers num="2.6.17.12"/>
        <vers num="2.6.17.13"/>
        <vers num="2.6.17.14"/>
        <vers num="2.6.17.2"/>
        <vers num="2.6.17.3"/>
        <vers num="2.6.17.4"/>
        <vers num="2.6.17.5"/>
        <vers num="2.6.17.6"/>
        <vers num="2.6.17.7"/>
        <vers num="2.6.17.8"/>
        <vers num="2.6.17.9"/>
        <vers num="2.6.18" edition="rc1"/>
        <vers num="2.6.18" edition="rc2"/>
        <vers num="2.6.18" edition="rc3"/>
        <vers num="2.6.18" edition="rc4"/>
        <vers num="2.6.18" edition="rc5"/>
        <vers num="2.6.18" edition="rc6"/>
        <vers num="2.6.18" edition="rc7"/>
        <vers num="2.6.18.1"/>
        <vers num="2.6.18.2"/>
        <vers num="2.6.18.3"/>
        <vers num="2.6.18.4"/>
        <vers num="2.6.18.5"/>
        <vers num="2.6.18.6"/>
        <vers num="2.6.18.7"/>
        <vers num="2.6.18.8"/>
        <vers num="2.6.19"/>
        <vers num="2.6.19.1"/>
        <vers num="2.6.19.2"/>
        <vers num="2.6.19.3"/>
        <vers num="2.6.19.4"/>
        <vers num="2.6.19.5"/>
        <vers num="2.6.19.6"/>
        <vers num="2.6.19.7"/>
        <vers num="2.6.2"/>
        <vers num="2.6.20"/>
        <vers num="2.6.20.1"/>
        <vers num="2.6.20.10"/>
        <vers num="2.6.20.11"/>
        <vers num="2.6.20.12"/>
        <vers num="2.6.20.13"/>
        <vers num="2.6.20.14"/>
        <vers num="2.6.20.15"/>
        <vers num="2.6.20.16"/>
        <vers num="2.6.20.17"/>
        <vers num="2.6.20.18"/>
        <vers num="2.6.20.19"/>
        <vers num="2.6.20.2"/>
        <vers num="2.6.20.20"/>
        <vers num="2.6.20.21"/>
        <vers num="2.6.20.3"/>
        <vers num="2.6.20.4"/>
        <vers num="2.6.20.5"/>
        <vers num="2.6.20.6"/>
        <vers num="2.6.20.7"/>
        <vers num="2.6.20.8"/>
        <vers num="2.6.20.9"/>
        <vers num="2.6.21"/>
        <vers num="2.6.21.1"/>
        <vers num="2.6.21.2"/>
        <vers num="2.6.21.3"/>
        <vers num="2.6.21.4"/>
        <vers num="2.6.21.5"/>
        <vers num="2.6.21.6"/>
        <vers num="2.6.21.7"/>
        <vers num="2.6.22"/>
        <vers num="2.6.22.1"/>
        <vers num="2.6.22.10"/>
        <vers num="2.6.22.11"/>
        <vers num="2.6.22.12"/>
        <vers num="2.6.22.13"/>
        <vers num="2.6.22.14"/>
        <vers num="2.6.22.15"/>
        <vers num="2.6.22.16"/>
        <vers num="2.6.22.17"/>
        <vers num="2.6.22.18"/>
        <vers num="2.6.22.19"/>
        <vers num="2.6.22.2"/>
        <vers num="2.6.22.20"/>
        <vers num="2.6.22.21"/>
        <vers num="2.6.22.22"/>
        <vers num="2.6.22.3"/>
        <vers num="2.6.22.4"/>
        <vers num="2.6.22.5"/>
        <vers num="2.6.22.6"/>
        <vers num="2.6.22.7"/>
        <vers num="2.6.22.8"/>
        <vers num="2.6.22.9"/>
        <vers num="2.6.22_rc1"/>
        <vers num="2.6.22_rc7"/>
        <vers num="2.6.23" edition="rc1"/>
        <vers num="2.6.23" edition="rc2"/>
        <vers num="2.6.23.1"/>
        <vers num="2.6.23.10"/>
        <vers num="2.6.23.11"/>
        <vers num="2.6.23.12"/>
        <vers num="2.6.23.13"/>
        <vers num="2.6.23.14"/>
        <vers num="2.6.23.15"/>
        <vers num="2.6.23.16"/>
        <vers num="2.6.23.17"/>
        <vers num="2.6.23.2"/>
        <vers num="2.6.23.3"/>
        <vers num="2.6.23.4"/>
        <vers num="2.6.23.5"/>
        <vers num="2.6.23.6"/>
        <vers num="2.6.23.7"/>
        <vers num="2.6.23.8"/>
        <vers num="2.6.23.9"/>
        <vers prev="1" num="2.6.24"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0025" published="2009-01-07" name="CVE-2009-0025" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00393.html" source="FEDORA">FEDORA-2009-0350</ref>
      <ref url="https://www.isc.org/software/bind/advisories/cve-2009-0025" source="CONFIRM">https://www.isc.org/software/bind/advisories/cve-2009-0025</ref>
      <ref url="https://issues.rpath.com/browse/RPL-2938" source="CONFIRM">https://issues.rpath.com/browse/RPL-2938</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0904" source="VUPEN">ADV-2009-0904</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0366" source="VUPEN">ADV-2009-0366</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0043" source="VUPEN">ADV-2009-0043</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0004.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0004.html</ref>
      <ref url="http://www.securityfocus.com/bid/33151" source="BID">33151</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502322/100/0/threaded" source="BUGTRAQ">20090401 VMSA-2009-0004 ESX Service Console updates for openssl, bind, and vim</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500207/100/0/threaded" source="BUGTRAQ">20090120 rPSA-2009-0009-1 bind bind-utils</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/499827/100/0/threaded" source="BUGTRAQ">20090107 [oCERT-2008-016] Multiple OpenSSL signature verification API misuses</ref>
      <ref url="http://www.openbsd.org/errata44.html#008_bind" source="CONFIRM">http://www.openbsd.org/errata44.html#008_bind</ref>
      <ref url="http://www.ocert.org/advisories/ocert-2008-016.html" source="MISC">http://www.ocert.org/advisories/ocert-2008-016.html</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0009" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0009</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-045.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-045.htm</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-250846-1" source="SUNALERT">250846</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.540362" source="SLACKWARE">SSA:2009-014-02</ref>
      <ref url="http://security.freebsd.org/advisories/FreeBSD-SA-09:04.bind.asc" source="FREEBSD">FreeBSD-SA-09:04</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://secunia.com/advisories/33882" source="SECUNIA">33882</ref>
      <ref url="http://secunia.com/advisories/33683" source="SECUNIA">33683</ref>
      <ref url="http://secunia.com/advisories/33559" source="SECUNIA">33559</ref>
      <ref url="http://secunia.com/advisories/33551" source="SECUNIA">33551</ref>
      <ref url="http://secunia.com/advisories/33546" source="SECUNIA">33546</ref>
      <ref url="http://secunia.com/advisories/33494" source="SECUNIA">33494</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5569" source="OVAL">oval:org.mitre.oval:def:5569</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10879" source="OVAL">oval:org.mitre.oval:def:10879</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
      <ref url="http://groups.google.com/group/comp.protocols.dns.bind/browse_thread/thread/49ef622c8329fd33" source="MISC">http://groups.google.com/group/comp.protocols.dns.bind/browse_thread/thread/49ef622c8329fd33</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="4"/>
        <vers num="4.9"/>
        <vers num="4.9.10"/>
        <vers num="4.9.2"/>
        <vers num="4.9.3"/>
        <vers num="4.9.4"/>
        <vers num="4.9.5" edition="p1"/>
        <vers num="4.9.6"/>
        <vers num="4.9.7"/>
        <vers num="4.9.8"/>
        <vers num="4.9.9"/>
        <vers num="8"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.1.2"/>
        <vers num="8.2" edition="p1"/>
        <vers num="8.2.1"/>
        <vers num="8.2.2" edition="p1"/>
        <vers num="8.2.2" edition="p2"/>
        <vers num="8.2.2" edition="p3"/>
        <vers num="8.2.2" edition="p4"/>
        <vers num="8.2.2" edition="p5"/>
        <vers num="8.2.2" edition="p6"/>
        <vers num="8.2.2" edition="p7"/>
        <vers num="8.2.3"/>
        <vers num="8.2.3_t1a"/>
        <vers num="8.2.3_t9b"/>
        <vers num="8.2.4"/>
        <vers num="8.2.5"/>
        <vers num="8.2.6"/>
        <vers num="8.2.7"/>
        <vers num="8.3.0"/>
        <vers num="8.3.1"/>
        <vers num="8.3.2"/>
        <vers num="8.3.3"/>
        <vers num="8.3.4"/>
        <vers num="8.3.5"/>
        <vers num="8.3.6"/>
        <vers num="8.4"/>
        <vers num="8.4.1"/>
        <vers num="8.4.4"/>
        <vers num="8.4.5"/>
        <vers num="8.4.7"/>
        <vers num="9.0"/>
        <vers num="9.0.1"/>
        <vers num="9.1"/>
        <vers num="9.1.1"/>
        <vers num="9.1.2"/>
        <vers num="9.1.3"/>
        <vers num="9.2"/>
        <vers num="9.2.0"/>
        <vers num="9.2.1"/>
        <vers num="9.2.2" edition="p3"/>
        <vers num="9.2.3"/>
        <vers num="9.2.4"/>
        <vers num="9.2.5"/>
        <vers num="9.2.6"/>
        <vers num="9.2.7"/>
        <vers num="9.2.9"/>
        <vers num="9.3"/>
        <vers num="9.3.0"/>
        <vers num="9.3.1"/>
        <vers num="9.3.2"/>
        <vers num="9.3.3"/>
        <vers num="9.3.5-p2-w1" edition="windows"/>
        <vers num="9.4"/>
        <vers num="9.4.0" edition="rc1"/>
        <vers num="9.4.0a1"/>
        <vers num="9.4.0a2"/>
        <vers num="9.4.0a3"/>
        <vers num="9.4.0a4"/>
        <vers num="9.4.0a5"/>
        <vers num="9.4.0a6"/>
        <vers num="9.4.0b1"/>
        <vers num="9.4.0b2"/>
        <vers num="9.4.0b3"/>
        <vers num="9.4.0b4"/>
        <vers num="9.4.1"/>
        <vers num="9.4.2"/>
        <vers prev="1" num="9.4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0026" published="2009-01-21" name="CVE-2009-0026" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) search.jsp or (2) swr.jsp.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://issues.apache.org/jira/browse/JCR-1925" source="CONFIRM" adv="1">https://issues.apache.org/jira/browse/JCR-1925</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48110" source="XF">jackrabbit-search-swr-xss(48110)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0177" source="VUPEN">ADV-2009-0177</ref>
      <ref url="http://www.securityfocus.com/bid/33360" source="BID">33360</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500196/100/0/threaded" source="BUGTRAQ">20090120 [ANNOUNCE] Apache Jackrabbit 1.5.2 released</ref>
      <ref url="http://www.apache.org/dist/jackrabbit/RELEASE-NOTES-1.5.2.txt" source="CONFIRM">http://www.apache.org/dist/jackrabbit/RELEASE-NOTES-1.5.2.txt</ref>
      <ref url="http://securityreason.com/securityalert/4942" source="SREASON">4942</ref>
      <ref url="http://secunia.com/advisories/33576" source="SECUNIA" adv="1">33576</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="jackrabbit">
        <vers num="1.4"/>
        <vers num="1.5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0027" published="2009-03-09" name="CVE-2009-0027" modified="2009-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The request handler in JBossWS in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP06 and 4.3 before 4.3.0.CP04 does not properly validate the resource path during a request for a WSDL file with a custom web-service endpoint, which allows remote attackers to read arbitrary XML files via a crafted request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0349.html" source="REDHAT" patch="1" adv="1">RHSA-2009:0349</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0347.html" source="REDHAT" patch="1">RHSA-2009:0347</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0346.html" source="REDHAT" patch="1">RHSA-2009:0346</ref>
      <ref url="https://jira.jboss.org/jira/browse/JBPAPP-1548" source="CONFIRM">https://jira.jboss.org/jira/browse/JBPAPP-1548</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=479668" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=479668</ref>
      <ref url="http://www.securitytracker.com/id?1021817" source="SECTRACK">1021817</ref>
      <ref url="http://www.securityfocus.com/bid/34023" source="BID">34023</ref>
      <ref url="http://secunia.com/advisories/34112" source="SECUNIA">34112</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0348.html" source="REDHAT" adv="1">RHSA-2009:0348</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="jboss_enterprise_application_platform">
        <vers num="4.2.0" edition="cp01"/>
        <vers num="4.2.0" edition="cp02"/>
        <vers num="4.2.0" edition="cp03"/>
        <vers num="4.2.0" edition="cp04"/>
        <vers num="4.2.0" edition="cp05"/>
        <vers num="4.2.0" edition="cp06"/>
        <vers num="4.3.0" edition="cp01"/>
        <vers num="4.3.0" edition="cp02"/>
        <vers num="4.3.0" edition="cp03"/>
        <vers num="4.3.0" edition="cp04"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0028" published="2009-02-27" name="CVE-2009-0028" modified="2012-03-19" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The clone system call in the Linux kernel 2.6.28 and earlier allows local users to send arbitrary signals to a parent process from an unprivileged child process by launching an additional child process with the CLONE_PARENT flag, and then letting this new process exit.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=479932" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=479932</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-751-1" source="UBUNTU">USN-751-1</ref>
      <ref url="http://www.securityfocus.com/bid/33906" source="BID">33906</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503610/100/0/threaded" source="BUGTRAQ">20090516 rPSA-2009-0084-1 kernel</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0451.html" source="REDHAT">RHSA-2009:0451</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0326.html" source="REDHAT">RHSA-2009:0326</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:118" source="MANDRIVA">MDVSA-2009:118</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1800" source="DEBIAN">DSA-1800</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1794" source="DEBIAN">DSA-1794</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1787" source="DEBIAN">DSA-1787</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0084" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0084</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA">37471</ref>
      <ref url="http://secunia.com/advisories/35394" source="SECUNIA">35394</ref>
      <ref url="http://secunia.com/advisories/35390" source="SECUNIA">35390</ref>
      <ref url="http://secunia.com/advisories/35121" source="SECUNIA">35121</ref>
      <ref url="http://secunia.com/advisories/35120" source="SECUNIA">35120</ref>
      <ref url="http://secunia.com/advisories/35011" source="SECUNIA">35011</ref>
      <ref url="http://secunia.com/advisories/34981" source="SECUNIA">34981</ref>
      <ref url="http://secunia.com/advisories/34962" source="SECUNIA">34962</ref>
      <ref url="http://secunia.com/advisories/34917" source="SECUNIA">34917</ref>
      <ref url="http://secunia.com/advisories/34680" source="SECUNIA">34680</ref>
      <ref url="http://secunia.com/advisories/34033" source="SECUNIA">34033</ref>
      <ref url="http://secunia.com/advisories/33758" source="SECUNIA">33758</ref>
      <ref url="http://scarybeastsecurity.blogspot.com/2009/02/linux-kernel-minor-signal-vulnerability.html" source="MISC">http://scarybeastsecurity.blogspot.com/2009/02/linux-kernel-minor-signal-vulnerability.html</ref>
      <ref url="http://scary.beasts.org/security/CESA-2009-002.html" source="MISC">http://scary.beasts.org/security/CESA-2009-002.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0459.html" source="REDHAT">RHSA-2009:0459</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7947" source="OVAL">oval:org.mitre.oval:def:7947</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11187" source="OVAL">oval:org.mitre.oval:def:11187</ref>
      <ref url="http://osvdb.org/52204" source="OSVDB">52204</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE">SUSE-SA:2009:031</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE">SUSE-SA:2009:030</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.html" source="SUSE">SUSE-SA:2009:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.2.27"/>
        <vers num="2.4.36"/>
        <vers num="2.4.36.1"/>
        <vers num="2.4.36.2"/>
        <vers num="2.4.36.3"/>
        <vers num="2.4.36.4"/>
        <vers num="2.4.36.5"/>
        <vers num="2.4.36.6"/>
        <vers num="2.6"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.10"/>
        <vers num="2.6.11"/>
        <vers num="2.6.11.1"/>
        <vers num="2.6.11.10"/>
        <vers num="2.6.11.11"/>
        <vers num="2.6.11.12"/>
        <vers num="2.6.11.2"/>
        <vers num="2.6.11.3"/>
        <vers num="2.6.11.4"/>
        <vers num="2.6.11.5"/>
        <vers num="2.6.11.6"/>
        <vers num="2.6.11.7"/>
        <vers num="2.6.11.8"/>
        <vers num="2.6.11.9"/>
        <vers num="2.6.12"/>
        <vers num="2.6.12.1"/>
        <vers num="2.6.12.2"/>
        <vers num="2.6.12.3"/>
        <vers num="2.6.12.4"/>
        <vers num="2.6.12.5"/>
        <vers num="2.6.12.6"/>
        <vers num="2.6.13"/>
        <vers num="2.6.13.1"/>
        <vers num="2.6.13.2"/>
        <vers num="2.6.13.3"/>
        <vers num="2.6.13.4"/>
        <vers num="2.6.13.5"/>
        <vers num="2.6.14"/>
        <vers num="2.6.14.1"/>
        <vers num="2.6.14.2"/>
        <vers num="2.6.14.3"/>
        <vers num="2.6.14.4"/>
        <vers num="2.6.14.5"/>
        <vers num="2.6.14.6"/>
        <vers num="2.6.14.7"/>
        <vers num="2.6.15"/>
        <vers num="2.6.15.1"/>
        <vers num="2.6.15.2"/>
        <vers num="2.6.15.3"/>
        <vers num="2.6.15.4"/>
        <vers num="2.6.15.5"/>
        <vers num="2.6.15.6"/>
        <vers num="2.6.15.7"/>
        <vers num="2.6.16"/>
        <vers num="2.6.16.1"/>
        <vers num="2.6.16.10"/>
        <vers num="2.6.16.11"/>
        <vers num="2.6.16.12"/>
        <vers num="2.6.16.13"/>
        <vers num="2.6.16.14"/>
        <vers num="2.6.16.15"/>
        <vers num="2.6.16.16"/>
        <vers num="2.6.16.17"/>
        <vers num="2.6.16.18"/>
        <vers num="2.6.16.19"/>
        <vers num="2.6.16.2"/>
        <vers num="2.6.16.20"/>
        <vers num="2.6.16.21"/>
        <vers num="2.6.16.22"/>
        <vers num="2.6.16.23"/>
        <vers num="2.6.16.24"/>
        <vers num="2.6.16.25"/>
        <vers num="2.6.16.26"/>
        <vers num="2.6.16.27"/>
        <vers num="2.6.16.28"/>
        <vers num="2.6.16.29"/>
        <vers num="2.6.16.3"/>
        <vers num="2.6.16.30"/>
        <vers num="2.6.16.31"/>
        <vers num="2.6.16.32"/>
        <vers num="2.6.16.33"/>
        <vers num="2.6.16.34"/>
        <vers num="2.6.16.35"/>
        <vers num="2.6.16.36"/>
        <vers num="2.6.16.37"/>
        <vers num="2.6.16.38"/>
        <vers num="2.6.16.39"/>
        <vers num="2.6.16.4"/>
        <vers num="2.6.16.40"/>
        <vers num="2.6.16.41"/>
        <vers num="2.6.16.42"/>
        <vers num="2.6.16.43"/>
        <vers num="2.6.16.44"/>
        <vers num="2.6.16.45"/>
        <vers num="2.6.16.46"/>
        <vers num="2.6.16.47"/>
        <vers num="2.6.16.48"/>
        <vers num="2.6.16.49"/>
        <vers num="2.6.16.5"/>
        <vers num="2.6.16.50"/>
        <vers num="2.6.16.51"/>
        <vers num="2.6.16.52"/>
        <vers num="2.6.16.53"/>
        <vers num="2.6.16.54"/>
        <vers num="2.6.16.55"/>
        <vers num="2.6.16.56"/>
        <vers num="2.6.16.57"/>
        <vers num="2.6.16.58"/>
        <vers num="2.6.16.59"/>
        <vers num="2.6.16.6"/>
        <vers num="2.6.16.60"/>
        <vers num="2.6.16.61"/>
        <vers num="2.6.16.62"/>
        <vers num="2.6.16.7"/>
        <vers num="2.6.16.8"/>
        <vers num="2.6.16.9"/>
        <vers num="2.6.17"/>
        <vers num="2.6.17.1"/>
        <vers num="2.6.17.10"/>
        <vers num="2.6.17.11"/>
        <vers num="2.6.17.12"/>
        <vers num="2.6.17.13"/>
        <vers num="2.6.17.14"/>
        <vers num="2.6.17.2"/>
        <vers num="2.6.17.3"/>
        <vers num="2.6.17.4"/>
        <vers num="2.6.17.5"/>
        <vers num="2.6.17.6"/>
        <vers num="2.6.17.7"/>
        <vers num="2.6.17.8"/>
        <vers num="2.6.17.9"/>
        <vers num="2.6.18" edition="rc1"/>
        <vers num="2.6.18" edition="rc2"/>
        <vers num="2.6.18" edition="rc3"/>
        <vers num="2.6.18" edition="rc4"/>
        <vers num="2.6.18" edition="rc5"/>
        <vers num="2.6.18" edition="rc6"/>
        <vers num="2.6.18" edition="rc7"/>
        <vers num="2.6.18.1"/>
        <vers num="2.6.18.2"/>
        <vers num="2.6.18.3"/>
        <vers num="2.6.18.4"/>
        <vers num="2.6.18.5"/>
        <vers num="2.6.18.6"/>
        <vers num="2.6.18.7"/>
        <vers num="2.6.18.8"/>
        <vers num="2.6.19"/>
        <vers num="2.6.19.1"/>
        <vers num="2.6.19.2"/>
        <vers num="2.6.19.3"/>
        <vers num="2.6.19.4"/>
        <vers num="2.6.19.5"/>
        <vers num="2.6.19.6"/>
        <vers num="2.6.19.7"/>
        <vers num="2.6.2"/>
        <vers num="2.6.20"/>
        <vers num="2.6.20.1"/>
        <vers num="2.6.20.10"/>
        <vers num="2.6.20.11"/>
        <vers num="2.6.20.12"/>
        <vers num="2.6.20.13"/>
        <vers num="2.6.20.14"/>
        <vers num="2.6.20.15"/>
        <vers num="2.6.20.16"/>
        <vers num="2.6.20.17"/>
        <vers num="2.6.20.18"/>
        <vers num="2.6.20.19"/>
        <vers num="2.6.20.2"/>
        <vers num="2.6.20.20"/>
        <vers num="2.6.20.21"/>
        <vers num="2.6.20.3"/>
        <vers num="2.6.20.4"/>
        <vers num="2.6.20.5"/>
        <vers num="2.6.20.6"/>
        <vers num="2.6.20.7"/>
        <vers num="2.6.20.8"/>
        <vers num="2.6.20.9"/>
        <vers num="2.6.21"/>
        <vers num="2.6.21.1"/>
        <vers num="2.6.21.2"/>
        <vers num="2.6.21.3"/>
        <vers num="2.6.21.4"/>
        <vers num="2.6.21.5"/>
        <vers num="2.6.21.6"/>
        <vers num="2.6.21.7"/>
        <vers num="2.6.22"/>
        <vers num="2.6.22.1"/>
        <vers num="2.6.22.10"/>
        <vers num="2.6.22.11"/>
        <vers num="2.6.22.12"/>
        <vers num="2.6.22.13"/>
        <vers num="2.6.22.14"/>
        <vers num="2.6.22.15"/>
        <vers num="2.6.22.16"/>
        <vers num="2.6.22.17"/>
        <vers num="2.6.22.18"/>
        <vers num="2.6.22.19"/>
        <vers num="2.6.22.2"/>
        <vers num="2.6.22.20"/>
        <vers num="2.6.22.21"/>
        <vers num="2.6.22.22"/>
        <vers num="2.6.22.3"/>
        <vers num="2.6.22.4"/>
        <vers num="2.6.22.5"/>
        <vers num="2.6.22.6"/>
        <vers num="2.6.22.7"/>
        <vers num="2.6.22.8"/>
        <vers num="2.6.22.9"/>
        <vers num="2.6.22_rc1"/>
        <vers num="2.6.22_rc7"/>
        <vers num="2.6.23" edition="rc1"/>
        <vers num="2.6.23" edition="rc2"/>
        <vers num="2.6.23.1"/>
        <vers num="2.6.23.10"/>
        <vers num="2.6.23.11"/>
        <vers num="2.6.23.12"/>
        <vers num="2.6.23.13"/>
        <vers num="2.6.23.14"/>
        <vers num="2.6.23.15"/>
        <vers num="2.6.23.16"/>
        <vers num="2.6.23.17"/>
        <vers num="2.6.23.2"/>
        <vers num="2.6.23.3"/>
        <vers num="2.6.23.4"/>
        <vers num="2.6.23.5"/>
        <vers num="2.6.23.6"/>
        <vers num="2.6.23.7"/>
        <vers num="2.6.23.8"/>
        <vers num="2.6.23.9"/>
        <vers num="2.6.23_rc1"/>
        <vers num="2.6.24" edition="rc1"/>
        <vers num="2.6.24" edition="rc2"/>
        <vers num="2.6.24" edition="rc3"/>
        <vers num="2.6.24" edition="rc4"/>
        <vers num="2.6.24" edition="rc5"/>
        <vers num="2.6.24.1"/>
        <vers num="2.6.24.2"/>
        <vers num="2.6.24.3"/>
        <vers num="2.6.24.4"/>
        <vers num="2.6.24.5"/>
        <vers num="2.6.24.6"/>
        <vers num="2.6.24.7"/>
        <vers num="2.6.24_rc1"/>
        <vers num="2.6.24_rc4"/>
        <vers num="2.6.24_rc5"/>
        <vers num="2.6.25" edition=""/>
        <vers num="2.6.25" edition=":x86_64"/>
        <vers num="2.6.25.1" edition=""/>
        <vers num="2.6.25.1" edition=":x86_64"/>
        <vers num="2.6.25.10" edition=""/>
        <vers num="2.6.25.10" edition=":x86_64"/>
        <vers num="2.6.25.11" edition=""/>
        <vers num="2.6.25.11" edition=":x86_64"/>
        <vers num="2.6.25.12" edition=""/>
        <vers num="2.6.25.12" edition=":x86_64"/>
        <vers num="2.6.25.13"/>
        <vers num="2.6.25.14"/>
        <vers num="2.6.25.15"/>
        <vers num="2.6.25.16"/>
        <vers num="2.6.25.17"/>
        <vers num="2.6.25.18"/>
        <vers num="2.6.25.19"/>
        <vers num="2.6.25.2" edition=""/>
        <vers num="2.6.25.2" edition=":x86_64"/>
        <vers num="2.6.25.20"/>
        <vers num="2.6.25.3" edition=""/>
        <vers num="2.6.25.3" edition=":x86_64"/>
        <vers num="2.6.25.4" edition=""/>
        <vers num="2.6.25.4" edition=":x86_64"/>
        <vers num="2.6.25.5" edition=""/>
        <vers num="2.6.25.5" edition=":x86_64"/>
        <vers num="2.6.25.6" edition=""/>
        <vers num="2.6.25.6" edition=":x86_64"/>
        <vers num="2.6.25.7" edition=""/>
        <vers num="2.6.25.7" edition=":x86_64"/>
        <vers num="2.6.25.8" edition=""/>
        <vers num="2.6.25.8" edition=":x86_64"/>
        <vers num="2.6.25.9" edition=""/>
        <vers num="2.6.25.9" edition=":x86_64"/>
        <vers num="2.6.26" edition="rc4"/>
        <vers num="2.6.26.1"/>
        <vers num="2.6.26.2"/>
        <vers num="2.6.26.3"/>
        <vers num="2.6.26.4"/>
        <vers num="2.6.26.5"/>
        <vers num="2.6.26.6"/>
        <vers num="2.6.26.7"/>
        <vers num="2.6.26.8"/>
        <vers num="2.6.27" edition="rc1"/>
        <vers num="2.6.27" edition="rc2"/>
        <vers num="2.6.27" edition="rc3"/>
        <vers num="2.6.27" edition="rc4"/>
        <vers num="2.6.27" edition="rc5"/>
        <vers num="2.6.27" edition="rc6"/>
        <vers num="2.6.27" edition="rc7"/>
        <vers num="2.6.27" edition="rc8"/>
        <vers num="2.6.27" edition="rc9"/>
        <vers num="2.6.27.1"/>
        <vers num="2.6.27.10"/>
        <vers num="2.6.27.11"/>
        <vers num="2.6.27.12"/>
        <vers num="2.6.27.2"/>
        <vers num="2.6.27.3"/>
        <vers num="2.6.27.4"/>
        <vers num="2.6.27.5"/>
        <vers num="2.6.27.6"/>
        <vers num="2.6.27.7"/>
        <vers num="2.6.27.8"/>
        <vers num="2.6.27.9"/>
        <vers prev="1" num="2.6.28"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0029" published="2009-01-15" name="CVE-2009-0029" modified="2012-03-19" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The ABI in the Linux kernel 2.6.28 and earlier on s390, powerpc, sparc64, and mips 64-bit platforms requires that a 32-bit argument in a 64-bit register was properly sign extended when sent from a user-mode application, but cannot verify this, which allows local users to cause a denial of service (crash) or possibly gain privileges via a crafted system call.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg01045.html" source="FEDORA">FEDORA-2009-0816</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=479969" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=479969</ref>
      <ref url="http://www.securityfocus.com/bid/33275" source="BID">33275</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:135" source="MANDRIVA">MDVSA-2009:135</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1794" source="DEBIAN">DSA-1794</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1787" source="DEBIAN">DSA-1787</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1749" source="DEBIAN">DSA-1749</ref>
      <ref url="http://secunia.com/advisories/35011" source="SECUNIA">35011</ref>
      <ref url="http://secunia.com/advisories/34981" source="SECUNIA">34981</ref>
      <ref url="http://secunia.com/advisories/34394" source="SECUNIA">34394</ref>
      <ref url="http://secunia.com/advisories/33674" source="SECUNIA">33674</ref>
      <ref url="http://secunia.com/advisories/33477" source="SECUNIA" adv="1">33477</ref>
      <ref url="http://marc.info/?l=linux-kernel&amp;m=123155111608910&amp;w=2" source="MLIST">[linux-kernel] 20090110 Re: [PATCH -v7][RFC]: mutex: implement adaptive spinning</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.html" source="SUSE">SUSE-SA:2009:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.2.27"/>
        <vers num="2.4.36"/>
        <vers num="2.4.36.1"/>
        <vers num="2.4.36.2"/>
        <vers num="2.4.36.3"/>
        <vers num="2.4.36.4"/>
        <vers num="2.4.36.5"/>
        <vers num="2.4.36.6"/>
        <vers num="2.6"/>
        <vers num="2.6.18" edition="rc1"/>
        <vers num="2.6.18" edition="rc2"/>
        <vers num="2.6.18" edition="rc3"/>
        <vers num="2.6.18" edition="rc4"/>
        <vers num="2.6.18" edition="rc5"/>
        <vers num="2.6.18" edition="rc6"/>
        <vers num="2.6.18" edition="rc7"/>
        <vers num="2.6.19.4"/>
        <vers num="2.6.19.5"/>
        <vers num="2.6.19.6"/>
        <vers num="2.6.19.7"/>
        <vers num="2.6.20.16"/>
        <vers num="2.6.20.17"/>
        <vers num="2.6.20.18"/>
        <vers num="2.6.20.19"/>
        <vers num="2.6.20.20"/>
        <vers num="2.6.20.21"/>
        <vers num="2.6.21.5"/>
        <vers num="2.6.21.6"/>
        <vers num="2.6.21.7"/>
        <vers num="2.6.22"/>
        <vers num="2.6.22.1"/>
        <vers num="2.6.22.10"/>
        <vers num="2.6.22.11"/>
        <vers num="2.6.22.12"/>
        <vers num="2.6.22.13"/>
        <vers num="2.6.22.14"/>
        <vers num="2.6.22.15"/>
        <vers num="2.6.22.17"/>
        <vers num="2.6.22.18"/>
        <vers num="2.6.22.19"/>
        <vers num="2.6.22.2"/>
        <vers num="2.6.22.20"/>
        <vers num="2.6.22.21"/>
        <vers num="2.6.22.22"/>
        <vers num="2.6.22.8"/>
        <vers num="2.6.22.9"/>
        <vers num="2.6.22_rc1"/>
        <vers num="2.6.22_rc7"/>
        <vers num="2.6.23"/>
        <vers num="2.6.23.10"/>
        <vers num="2.6.23.11"/>
        <vers num="2.6.23.12"/>
        <vers num="2.6.23.13"/>
        <vers num="2.6.23.15"/>
        <vers num="2.6.23.16"/>
        <vers num="2.6.23.17"/>
        <vers num="2.6.23.8"/>
        <vers num="2.6.23.9"/>
        <vers num="2.6.23_rc1"/>
        <vers num="2.6.24"/>
        <vers num="2.6.24.1"/>
        <vers num="2.6.24.2"/>
        <vers num="2.6.24.3"/>
        <vers num="2.6.24.4"/>
        <vers num="2.6.24.5"/>
        <vers num="2.6.24.6"/>
        <vers num="2.6.24.7"/>
        <vers num="2.6.24_rc1"/>
        <vers num="2.6.24_rc4"/>
        <vers num="2.6.24_rc5"/>
        <vers num="2.6.25" edition=""/>
        <vers num="2.6.25" edition=":x86_64"/>
        <vers num="2.6.25.1" edition=""/>
        <vers num="2.6.25.1" edition=":x86_64"/>
        <vers num="2.6.25.10" edition=""/>
        <vers num="2.6.25.10" edition=":x86_64"/>
        <vers num="2.6.25.11" edition=""/>
        <vers num="2.6.25.11" edition=":x86_64"/>
        <vers num="2.6.25.12" edition=""/>
        <vers num="2.6.25.12" edition=":x86_64"/>
        <vers num="2.6.25.13"/>
        <vers num="2.6.25.14"/>
        <vers num="2.6.25.15"/>
        <vers num="2.6.25.16"/>
        <vers num="2.6.25.17"/>
        <vers num="2.6.25.2" edition=""/>
        <vers num="2.6.25.2" edition=":x86_64"/>
        <vers num="2.6.25.3" edition=""/>
        <vers num="2.6.25.3" edition=":x86_64"/>
        <vers num="2.6.25.4" edition=""/>
        <vers num="2.6.25.4" edition=":x86_64"/>
        <vers num="2.6.25.5" edition=""/>
        <vers num="2.6.25.5" edition=":x86_64"/>
        <vers num="2.6.25.6" edition=""/>
        <vers num="2.6.25.6" edition=":x86_64"/>
        <vers num="2.6.25.7" edition=""/>
        <vers num="2.6.25.7" edition=":x86_64"/>
        <vers num="2.6.25.8" edition=""/>
        <vers num="2.6.25.8" edition=":x86_64"/>
        <vers num="2.6.25.9" edition=""/>
        <vers num="2.6.25.9" edition=":x86_64"/>
        <vers num="2.6.26"/>
        <vers num="2.6.26.1"/>
        <vers num="2.6.26.2"/>
        <vers num="2.6.26.3"/>
        <vers num="2.6.26.4"/>
        <vers num="2.6.26.5"/>
        <vers num="2.6.27"/>
        <vers prev="1" num="2.6.28"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0030" published="2009-01-21" name="CVE-2009-0030" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">A certain Red Hat patch for SquirrelMail 1.4.8 sets the same SQMSESSID cookie value for all sessions, which allows remote authenticated users to access other users' folder lists and configuration data in opportunistic circumstances by using the standard webmail.php interface.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-3663.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-0057.html" source="REDHAT">RHSA-2009:0057</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=480488" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=480488</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=480224" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=480224</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48115" source="XF">squirrelmail-sessionid-session-hijacking(48115)</ref>
      <ref url="http://www.securityfocus.com/bid/33354" source="BID">33354</ref>
      <ref url="http://securitytracker.com/id?1021611" source="SECTRACK">1021611</ref>
      <ref url="http://secunia.com/advisories/33611" source="SECUNIA" adv="1">33611</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10366" source="OVAL">oval:org.mitre.oval:def:10366</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html" source="SUSE">SUSE-SR:2009:004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.4.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0031" published="2009-01-20" name="CVE-2009-0031" modified="2012-03-19" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Memory leak in the keyctl_join_session_keyring function (security/keys/keyctl.c) in Linux kernel 2.6.29-rc2 and earlier allows local users to cause a denial of service (kernel memory consumption) via unknown vectors related to a "missing kfree."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.ubuntu.com/usn/usn-751-1" source="UBUNTU">USN-751-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0360.html" source="REDHAT">RHSA-2009:0360</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0331.html" source="REDHAT">RHSA-2009:0331</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/19/4" source="MLIST">[oss-security] 20090119 CVE-2009-0031 kernel: local denial of service in keyctl_join_session_keyring</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1794" source="DEBIAN">DSA-1794</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1787" source="DEBIAN">DSA-1787</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1749" source="DEBIAN">DSA-1749</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-114.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-114.htm</ref>
      <ref url="http://secunia.com/advisories/35011" source="SECUNIA">35011</ref>
      <ref url="http://secunia.com/advisories/34981" source="SECUNIA">34981</ref>
      <ref url="http://secunia.com/advisories/34762" source="SECUNIA">34762</ref>
      <ref url="http://secunia.com/advisories/34502" source="SECUNIA">34502</ref>
      <ref url="http://secunia.com/advisories/34394" source="SECUNIA">34394</ref>
      <ref url="http://secunia.com/advisories/34252" source="SECUNIA">34252</ref>
      <ref url="http://secunia.com/advisories/33858" source="SECUNIA">33858</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0264.html" source="REDHAT">RHSA-2009:0264</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11386" source="OVAL">oval:org.mitre.oval:def:11386</ref>
      <ref url="http://osvdb.org/51501" source="OSVDB">51501</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.html" source="SUSE">SUSE-SA:2009:010</ref>
      <ref url="http://git2.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=0d54ee1c7850a954026deec4cd4885f331da35cc" source="CONFIRM">http://git2.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=0d54ee1c7850a954026deec4cd4885f331da35cc</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.2.27"/>
        <vers num="2.4.36"/>
        <vers num="2.4.36.1"/>
        <vers num="2.4.36.2"/>
        <vers num="2.4.36.3"/>
        <vers num="2.4.36.4"/>
        <vers num="2.4.36.5"/>
        <vers num="2.4.36.6"/>
        <vers num="2.6"/>
        <vers num="2.6.18" edition="rc1"/>
        <vers num="2.6.18" edition="rc2"/>
        <vers num="2.6.18" edition="rc3"/>
        <vers num="2.6.18" edition="rc4"/>
        <vers num="2.6.18" edition="rc5"/>
        <vers num="2.6.18" edition="rc6"/>
        <vers num="2.6.18" edition="rc7"/>
        <vers num="2.6.19.4"/>
        <vers num="2.6.19.5"/>
        <vers num="2.6.19.6"/>
        <vers num="2.6.19.7"/>
        <vers num="2.6.20.16"/>
        <vers num="2.6.20.17"/>
        <vers num="2.6.20.18"/>
        <vers num="2.6.20.19"/>
        <vers num="2.6.20.20"/>
        <vers num="2.6.20.21"/>
        <vers num="2.6.21.5"/>
        <vers num="2.6.21.6"/>
        <vers num="2.6.21.7"/>
        <vers num="2.6.22"/>
        <vers num="2.6.22.1"/>
        <vers num="2.6.22.10"/>
        <vers num="2.6.22.11"/>
        <vers num="2.6.22.12"/>
        <vers num="2.6.22.13"/>
        <vers num="2.6.22.14"/>
        <vers num="2.6.22.15"/>
        <vers num="2.6.22.17"/>
        <vers num="2.6.22.18"/>
        <vers num="2.6.22.19"/>
        <vers num="2.6.22.2"/>
        <vers num="2.6.22.20"/>
        <vers num="2.6.22.21"/>
        <vers num="2.6.22.22"/>
        <vers num="2.6.22.8"/>
        <vers num="2.6.22.9"/>
        <vers num="2.6.22_rc1"/>
        <vers num="2.6.22_rc7"/>
        <vers num="2.6.23"/>
        <vers num="2.6.23.10"/>
        <vers num="2.6.23.11"/>
        <vers num="2.6.23.12"/>
        <vers num="2.6.23.13"/>
        <vers num="2.6.23.15"/>
        <vers num="2.6.23.16"/>
        <vers num="2.6.23.17"/>
        <vers num="2.6.23.8"/>
        <vers num="2.6.23.9"/>
        <vers num="2.6.23_rc1"/>
        <vers num="2.6.24"/>
        <vers num="2.6.24.1"/>
        <vers num="2.6.24.2"/>
        <vers num="2.6.24.3"/>
        <vers num="2.6.24.4"/>
        <vers num="2.6.24.5"/>
        <vers num="2.6.24.6"/>
        <vers num="2.6.24.7"/>
        <vers num="2.6.24_rc1"/>
        <vers num="2.6.24_rc4"/>
        <vers num="2.6.24_rc5"/>
        <vers num="2.6.25" edition=""/>
        <vers num="2.6.25" edition=":x86_64"/>
        <vers num="2.6.25.1" edition=""/>
        <vers num="2.6.25.1" edition=":x86_64"/>
        <vers num="2.6.25.10" edition=""/>
        <vers num="2.6.25.10" edition=":x86_64"/>
        <vers num="2.6.25.11" edition=""/>
        <vers num="2.6.25.11" edition=":x86_64"/>
        <vers num="2.6.25.12" edition=""/>
        <vers num="2.6.25.12" edition=":x86_64"/>
        <vers num="2.6.25.13"/>
        <vers num="2.6.25.14"/>
        <vers num="2.6.25.15"/>
        <vers num="2.6.25.16"/>
        <vers num="2.6.25.17"/>
        <vers num="2.6.25.2" edition=""/>
        <vers num="2.6.25.2" edition=":x86_64"/>
        <vers num="2.6.25.3" edition=""/>
        <vers num="2.6.25.3" edition=":x86_64"/>
        <vers num="2.6.25.4" edition=""/>
        <vers num="2.6.25.4" edition=":x86_64"/>
        <vers num="2.6.25.5" edition=""/>
        <vers num="2.6.25.5" edition=":x86_64"/>
        <vers num="2.6.25.6" edition=""/>
        <vers num="2.6.25.6" edition=":x86_64"/>
        <vers num="2.6.25.7" edition=""/>
        <vers num="2.6.25.7" edition=":x86_64"/>
        <vers num="2.6.25.8" edition=""/>
        <vers num="2.6.25.8" edition=":x86_64"/>
        <vers num="2.6.25.9" edition=""/>
        <vers num="2.6.25.9" edition=":x86_64"/>
        <vers num="2.6.26"/>
        <vers num="2.6.26.1"/>
        <vers num="2.6.26.2"/>
        <vers num="2.6.26.3"/>
        <vers num="2.6.26.4"/>
        <vers num="2.6.26.5"/>
        <vers num="2.6.27"/>
        <vers num="2.6.28"/>
        <vers prev="1" num="2.6.28.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0032" published="2009-01-27" name="CVE-2009-0032" modified="2009-01-28" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48210" source="XF">cups-pdflog-symlink(48210)</ref>
      <ref url="http://www.securityfocus.com/bid/33418" source="BID">33418</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:029" source="MANDRIVA" adv="1">MDVSA-2009:029</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:028" source="MANDRIVA">MDVSA-2009:028</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:027" source="MANDRIVA" adv="1">MDVSA-2009:027</ref>
      <ref url="http://securitytracker.com/id?1021637" source="SECTRACK">1021637</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0033" published="2009-06-05" name="CVE-2009-0033" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_jk load balancing are used, allows remote attackers to cause a denial of service (application outage) via a crafted request with invalid headers, related to temporary blocking of connectors that have encountered errors, as demonstrated by an error involving a malformed HTTP Host header.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1496" source="VUPEN" patch="1" adv="1">ADV-2009-1496</ref>
      <ref url="http://www.securityfocus.com/bid/35193" source="BID" patch="1">35193</ref>
      <ref url="http://tomcat.apache.org/security-6.html" source="CONFIRM" patch="1" adv="1">http://tomcat.apache.org/security-6.html</ref>
      <ref url="http://tomcat.apache.org/security-5.html" source="CONFIRM" patch="1" adv="1">http://tomcat.apache.org/security-5.html</ref>
      <ref url="http://tomcat.apache.org/security-4.html" source="CONFIRM" patch="1" adv="1">http://tomcat.apache.org/security-4.html</ref>
      <ref url="http://svn.apache.org/viewvc?rev=781362&amp;view=rev" source="CONFIRM" patch="1" adv="1">http://svn.apache.org/viewvc?rev=781362&amp;view=rev</ref>
      <ref url="http://svn.apache.org/viewvc?rev=742915&amp;view=rev" source="CONFIRM" patch="1" adv="1">http://svn.apache.org/viewvc?rev=742915&amp;view=rev</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01246.html" source="FEDORA">FEDORA-2009-11356</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01216.html" source="FEDORA">FEDORA-2009-11352</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01156.html" source="FEDORA">FEDORA-2009-11374</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50928" source="XF">tomcat-ajp-dos(50928)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3056" source="VUPEN">ADV-2010-3056</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1856" source="VUPEN">ADV-2009-1856</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504044/100/0/threaded" source="BUGTRAQ">20090603 [SECURITY] CVE-2009-0033 Apache Tomcat DoS when using Java AJP connector</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:176" source="MANDRIVA">MDVSA-2010:176</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:138" source="MANDRIVA">MDVSA-2009:138</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:136" source="MANDRIVA">MDVSA-2009:136</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2207" source="DEBIAN">DSA-2207</ref>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-263529-1" source="SUNALERT">263529</ref>
      <ref url="http://securitytracker.com/id?1022331" source="SECTRACK">1022331</ref>
      <ref url="http://secunia.com/advisories/42368" source="SECUNIA">42368</ref>
      <ref url="http://secunia.com/advisories/37460" source="SECUNIA">37460</ref>
      <ref url="http://secunia.com/advisories/35788" source="SECUNIA">35788</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://secunia.com/advisories/35344" source="SECUNIA" adv="1">35344</ref>
      <ref url="http://secunia.com/advisories/35326" source="SECUNIA" adv="1">35326</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5739" source="OVAL">oval:org.mitre.oval:def:5739</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10231" source="OVAL">oval:org.mitre.oval:def:10231</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136485229118404&amp;w=2" source="HP">SSRT101146</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136485229118404&amp;w=2" source="HP">HPSBUX02860</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129070310906557&amp;w=2" source="HP">SSRT100203</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129070310906557&amp;w=2" source="HP">SSRT100203</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE">APPLE-SA-2010-03-29-1</ref>
      <ref url="http://jvn.jp/en/jp/JVN87272440/index.html" source="JVN">JVN#87272440</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers num="4.1.0"/>
        <vers num="4.1.1"/>
        <vers num="4.1.10"/>
        <vers num="4.1.11"/>
        <vers num="4.1.12"/>
        <vers num="4.1.13"/>
        <vers num="4.1.14"/>
        <vers num="4.1.15"/>
        <vers num="4.1.16"/>
        <vers num="4.1.17"/>
        <vers num="4.1.18"/>
        <vers num="4.1.19"/>
        <vers num="4.1.2"/>
        <vers num="4.1.20"/>
        <vers num="4.1.21"/>
        <vers num="4.1.22"/>
        <vers num="4.1.23"/>
        <vers num="4.1.24"/>
        <vers num="4.1.25"/>
        <vers num="4.1.26"/>
        <vers num="4.1.27"/>
        <vers num="4.1.28"/>
        <vers num="4.1.29"/>
        <vers num="4.1.3" edition="beta"/>
        <vers num="4.1.30"/>
        <vers num="4.1.31"/>
        <vers num="4.1.32"/>
        <vers num="4.1.33"/>
        <vers num="4.1.34"/>
        <vers num="4.1.35"/>
        <vers num="4.1.36"/>
        <vers num="4.1.37"/>
        <vers num="4.1.38"/>
        <vers num="4.1.39"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.1.6"/>
        <vers num="4.1.7"/>
        <vers num="4.1.8"/>
        <vers num="4.1.9" edition="beta"/>
        <vers num="5.5.0"/>
        <vers num="5.5.1"/>
        <vers num="5.5.10"/>
        <vers num="5.5.11"/>
        <vers num="5.5.12"/>
        <vers num="5.5.13"/>
        <vers num="5.5.14"/>
        <vers num="5.5.15"/>
        <vers num="5.5.16"/>
        <vers num="5.5.17"/>
        <vers num="5.5.18"/>
        <vers num="5.5.19"/>
        <vers num="5.5.2"/>
        <vers num="5.5.20"/>
        <vers num="5.5.21"/>
        <vers num="5.5.22"/>
        <vers num="5.5.23"/>
        <vers num="5.5.24"/>
        <vers num="5.5.25"/>
        <vers num="5.5.26"/>
        <vers num="5.5.27"/>
        <vers num="5.5.3"/>
        <vers num="5.5.4"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.5.7"/>
        <vers num="5.5.8"/>
        <vers num="5.5.9"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.10"/>
        <vers num="6.0.11"/>
        <vers num="6.0.12"/>
        <vers num="6.0.13"/>
        <vers num="6.0.14"/>
        <vers num="6.0.15"/>
        <vers num="6.0.16"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.5"/>
        <vers num="6.0.6"/>
        <vers num="6.0.7"/>
        <vers num="6.0.8"/>
        <vers num="6.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0034" published="2009-01-30" name="CVE-2009-0034" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://issues.rpath.com/browse/RPL-2954" source="CONFIRM">https://issues.rpath.com/browse/RPL-2954</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=468923" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=468923</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1865" source="VUPEN">ADV-2009-1865</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0009.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0009.html</ref>
      <ref url="http://www.sudo.ws/cgi-bin/cvsweb/sudo/parse.c.diff?r1=1.160.2.21&amp;r2=1.160.2.22&amp;f=h" source="CONFIRM">http://www.sudo.ws/cgi-bin/cvsweb/sudo/parse.c.diff?r1=1.160.2.21&amp;r2=1.160.2.22&amp;f=h</ref>
      <ref url="http://www.securitytracker.com/id?1021688" source="SECTRACK">1021688</ref>
      <ref url="http://www.securityfocus.com/bid/33517" source="BID">33517</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504849/100/0/threaded" source="BUGTRAQ">20090711 VMSA-2009-0009 ESX Service Console updates for udev, sudo, and curl</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500546/100/0/threaded" source="BUGTRAQ">20090129 rPSA-2009-0021-1 sudo</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0267.html" source="REDHAT">RHSA-2009:0267</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:033" source="MANDRIVA">MDVSA-2009:033</ref>
      <ref url="http://www.gratisoft.us/bugzilla/show_bug.cgi?id=327" source="CONFIRM">http://www.gratisoft.us/bugzilla/show_bug.cgi?id=327</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0021" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0021</ref>
      <ref url="http://secunia.com/advisories/35766" source="SECUNIA">35766</ref>
      <ref url="http://secunia.com/advisories/33885" source="SECUNIA">33885</ref>
      <ref url="http://secunia.com/advisories/33840" source="SECUNIA">33840</ref>
      <ref url="http://secunia.com/advisories/33753" source="SECUNIA">33753</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6462" source="OVAL">oval:org.mitre.oval:def:6462</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10856" source="OVAL">oval:org.mitre.oval:def:10856</ref>
      <ref url="http://osvdb.org/51736" source="OSVDB">51736</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2009/000060.html" source="MLIST">[Security-announce] 20090710 VMSA-2009-0009 ESX Service Console updates for udev, sudo, and curl</ref>
    </refs>
    <vuln_soft>
      <prod vendor="todd_miller" name="sudo">
        <vers num="1.6.9_p17"/>
        <vers num="1.6.9_p18"/>
        <vers num="1.6.9_p19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0036" published="2009-02-11" name="CVE-2009-0036" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Buffer overflow in the proxyReadClientSocket function in proxy/libvirt_proxy.c in libvirt_proxy 0.5.1 might allow local users to gain privileges by sending a portion of the header of a virProxyPacket packet, and then sending the remainder of the packet with crafted values in the header, related to use of uninitialized memory in a validation check.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/libvir-list/2009-January/msg00728.html" source="MLIST" adv="1">[libvir-list] 20090128 Re: [libvirt] [PATCH] proxy: Fix use of uninitalized memory</ref>
      <ref url="https://www.redhat.com/archives/libvir-list/2009-January/msg00726.html" source="MLIST" adv="1">[libvir-list] 20090128 Re: [libvirt] [PATCH] proxy: Fix use of uninitalized memory</ref>
      <ref url="https://www.redhat.com/archives/libvir-list/2009-January/msg00699.html" source="MLIST" adv="1">[libvir-list] 20090127 [libvirt] [PATCH] proxy: Fix use of uninitalized memory</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=484947" source="CONFIRM" adv="1">https://bugzilla.redhat.com/show_bug.cgi?id=484947</ref>
      <ref url="http://www.securityfocus.com/bid/33724" source="BID">33724</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0382.html" source="REDHAT">RHSA-2009:0382</ref>
      <ref url="http://secunia.com/advisories/34397" source="SECUNIA">34397</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10127" source="OVAL">oval:org.mitre.oval:def:10127</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/02/10/8" source="MLIST">[oss-security] 20090210 libvirt_proxy heads up</ref>
      <ref url="http://git.et.redhat.com/?p=libvirt.git;a=commitdiff;h=2bb0657e28" source="CONFIRM" adv="1">http://git.et.redhat.com/?p=libvirt.git;a=commitdiff;h=2bb0657e28</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libvirt" name="libvirt">
        <vers num="0.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0037" published="2009-03-04" name="CVE-2009-0037" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location values, which might allow remote HTTP servers to (1) trigger arbitrary requests to intranet servers, (2) read or overwrite arbitrary files via a redirect to a file: URL, or (3) execute arbitrary commands via a redirect to an scp: URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0581" source="VUPEN" patch="1" adv="1">ADV-2009-0581</ref>
      <ref url="http://www.securityfocus.com/bid/33962" source="BID" patch="1">33962</ref>
      <ref url="http://curl.haxx.se/lxr/source/CHANGES" source="CONFIRM" patch="1" adv="1">http://curl.haxx.se/lxr/source/CHANGES</ref>
      <ref url="http://curl.haxx.se/docs/adv_20090303.html" source="CONFIRM" patch="1" adv="1">http://curl.haxx.se/docs/adv_20090303.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49030" source="XF">curl-location-security-bypass(49030)</ref>
      <ref url="http://www.withdk.com/archives/Libcurl_arbitrary_file_access.pdf" source="MISC">http://www.withdk.com/archives/Libcurl_arbitrary_file_access.pdf</ref>
      <ref url="http://www.withdk.com/2009/03/03/curllibcurl-redirect-arbitrary-file-access/" source="MISC">http://www.withdk.com/2009/03/03/curllibcurl-redirect-arbitrary-file-access/</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1865" source="VUPEN">ADV-2009-1865</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0009.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0009.html</ref>
      <ref url="http://www.ubuntu.com/usn/USN-726-1" source="UBUNTU">USN-726-1</ref>
      <ref url="http://www.securitytracker.com/id?1021783" source="SECTRACK">1021783</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504849/100/0/threaded" source="BUGTRAQ">20090711 VMSA-2009-0009 ESX Service Console updates for udev, sudo, and curl</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501757/100/0/threaded" source="BUGTRAQ">20090312 rPSA-2009-0042-1 curl</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0341.html" source="REDHAT">RHSA-2009:0341</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1738" source="DEBIAN">DSA-1738</ref>
      <ref url="http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0042" source="CONFIRM">http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0042</ref>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.476602" source="SLACKWARE">SSA:2009-069-01</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200903-21.xml" source="GENTOO">GLSA-200903-21</ref>
      <ref url="http://secunia.com/advisories/35766" source="SECUNIA">35766</ref>
      <ref url="http://secunia.com/advisories/34399" source="SECUNIA">34399</ref>
      <ref url="http://secunia.com/advisories/34259" source="SECUNIA">34259</ref>
      <ref url="http://secunia.com/advisories/34255" source="SECUNIA">34255</ref>
      <ref url="http://secunia.com/advisories/34251" source="SECUNIA">34251</ref>
      <ref url="http://secunia.com/advisories/34237" source="SECUNIA">34237</ref>
      <ref url="http://secunia.com/advisories/34202" source="SECUNIA">34202</ref>
      <ref url="http://secunia.com/advisories/34138" source="SECUNIA" adv="1">34138</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6074" source="OVAL">oval:org.mitre.oval:def:6074</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11054" source="OVAL">oval:org.mitre.oval:def:11054</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2009/000060.html" source="MLIST">[Security-announce] 20090710 VMSA-2009-0009 ESX Service Console updates for udev, sudo, and curl</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.html" source="SUSE">SUSE-SR:2009:006</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="curl" name="curl">
        <vers num="5.11"/>
        <vers num="6.0"/>
        <vers num="6.1beta"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.3.1"/>
        <vers num="6.4"/>
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="7.1"/>
        <vers num="7.1.1"/>
        <vers num="7.10"/>
        <vers num="7.10.1"/>
        <vers num="7.10.2"/>
        <vers num="7.10.3"/>
        <vers num="7.10.4"/>
        <vers num="7.10.5"/>
        <vers num="7.10.6"/>
        <vers num="7.10.7"/>
        <vers num="7.10.8"/>
        <vers num="7.11.1"/>
        <vers num="7.12"/>
        <vers num="7.12.1"/>
        <vers num="7.12.2"/>
        <vers num="7.13"/>
        <vers num="7.13.2"/>
        <vers num="7.14"/>
        <vers num="7.14.1"/>
        <vers num="7.15"/>
        <vers num="7.15.1"/>
        <vers num="7.15.3"/>
        <vers num="7.16.3"/>
        <vers num="7.16.4"/>
        <vers num="7.17"/>
        <vers num="7.18"/>
        <vers num="7.19.3"/>
        <vers num="7.2"/>
        <vers num="7.2.1"/>
        <vers num="7.3"/>
        <vers num="7.4"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.5"/>
        <vers num="7.5.1"/>
        <vers num="7.5.2"/>
        <vers num="7.6"/>
        <vers num="7.6.1"/>
        <vers num="7.7"/>
        <vers num="7.7.1"/>
        <vers num="7.7.2"/>
        <vers num="7.7.3"/>
        <vers num="7.8"/>
        <vers num="7.8.1"/>
        <vers num="7.8.2"/>
        <vers num="7.9"/>
        <vers num="7.9.1"/>
        <vers num="7.9.2"/>
        <vers num="7.9.3"/>
        <vers num="7.9.4"/>
        <vers num="7.9.5"/>
        <vers num="7.9.6"/>
        <vers num="7.9.7"/>
        <vers num="7.9.8"/>
      </prod>
      <prod vendor="curl" name="libcurl">
        <vers num="5.11"/>
        <vers num="7.12"/>
        <vers num="7.12.1"/>
        <vers num="7.12.2"/>
        <vers num="7.12.3"/>
        <vers num="7.13"/>
        <vers num="7.13.1"/>
        <vers num="7.13.2"/>
        <vers num="7.14"/>
        <vers num="7.14.1"/>
        <vers num="7.15"/>
        <vers num="7.15.1"/>
        <vers num="7.15.2"/>
        <vers num="7.15.3"/>
        <vers num="7.16.3"/>
        <vers num="7.19.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0038" published="2009-04-17" name="CVE-2009-0038" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) ip, (3) username, or (4) description parameter to console/portal/Server/Monitoring; or (5) the PATH_INFO to the default URI under console/portal/.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://issues.apache.org/jira/browse/GERONIMO-4597" source="CONFIRM" patch="1">http://issues.apache.org/jira/browse/GERONIMO-4597</ref>
      <ref url="http://geronimo.apache.org/21x-security-report.html#2.1.xSecurityReport-214" source="CONFIRM" patch="1" adv="1">http://geronimo.apache.org/21x-security-report.html#2.1.xSecurityReport-214</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1089" source="VUPEN">ADV-2009-1089</ref>
      <ref url="http://www.securityfocus.com/bid/34562" source="BID">34562</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502734/100/0/threaded" source="BUGTRAQ">20090416 [DSECRG-09-019] Apache Geronimo - XSS vulnerabilities.txt</ref>
      <ref url="http://secunia.com/advisories/34715" source="SECUNIA">34715</ref>
      <ref url="http://dsecrg.com/pages/vul/show.php?id=119" source="MISC">http://dsecrg.com/pages/vul/show.php?id=119</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="geronimo">
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0039" published="2009-04-17" name="CVE-2009-0039" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to hijack the authentication of administrators for requests that (1) change the web administration password, (2) upload applications, and perform unspecified other administrative actions, as demonstrated by (3) a Shutdown request to console/portal//Server/Shutdown.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1089" source="VUPEN">ADV-2009-1089</ref>
      <ref url="http://www.securityfocus.com/bid/34562" source="BID">34562</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502735/100/0/threaded" source="BUGTRAQ">20090416 [DSECRG-09-020] Apache Geronimo - XSRF vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/34715" source="SECUNIA">34715</ref>
      <ref url="http://issues.apache.org/jira/browse/GERONIMO-4597" source="CONFIRM" adv="1">http://issues.apache.org/jira/browse/GERONIMO-4597</ref>
      <ref url="http://geronimo.apache.org/21x-security-report.html#2.1.xSecurityReport-214" source="CONFIRM" adv="1">http://geronimo.apache.org/21x-security-report.html#2.1.xSecurityReport-214</ref>
      <ref url="http://dsecrg.com/pages/vul/show.php?id=120" source="MISC">http://dsecrg.com/pages/vul/show.php?id=120</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="geronimo">
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0040" published="2009-02-22" name="CVE-2009-0040" modified="2013-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file that triggers a free of an uninitialized pointer in (1) the png_read_png function, (2) pCAL chunk handling, or (3) setup of 16-bit gamma tables.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-218A.html" source="CERT">TA09-218A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/649212" source="CERT-VN">VU#649212</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00771.html" source="FEDORA">FEDORA-2009-2884</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00769.html" source="FEDORA">FEDORA-2009-2882</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00412.html" source="FEDORA">FEDORA-2009-1976</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00272.html" source="FEDORA">FEDORA-2009-2045</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48819" source="XF">libpng-pointer-arrays-code-execution(48819)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2172" source="VUPEN">ADV-2009-2172</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1560" source="VUPEN">ADV-2009-1560</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN">ADV-2009-1522</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1462" source="VUPEN">ADV-2009-1462</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1451" source="VUPEN">ADV-2009-1451</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0632" source="VUPEN">ADV-2009-0632</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0473" source="VUPEN">ADV-2009-0473</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0469" source="VUPEN">ADV-2009-0469</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0007.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0007.html</ref>
      <ref url="http://www.securityfocus.com/bid/33990" source="BID">33990</ref>
      <ref url="http://www.securityfocus.com/bid/33827" source="BID">33827</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/505990/100/0/threaded" source="BUGTRAQ">20090821 VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503912/100/0/threaded" source="BUGTRAQ">20090529 VMSA-2009-0007 VMware Hosted products and ESX and ESXi patches resolve security issues</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501767/100/0/threaded" source="BUGTRAQ">20090312 rPSA-2009-0046-1 libpng</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0340.html" source="REDHAT">RHSA-2009:0340</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0333.html" source="REDHAT">RHSA-2009:0333</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0325.html" source="REDHAT">RHSA-2009:0325</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0315.html" source="REDHAT">RHSA-2009:0315</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:083" source="MANDRIVA">MDVSA-2009:083</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:075" source="MANDRIVA">MDVSA-2009:075</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:051" source="MANDRIVA">MDVSA-2009:051</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1830" source="DEBIAN">DSA-1830</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1750" source="DEBIAN">DSA-1750</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0046" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0046</ref>
      <ref url="http://support.avaya.com/japple/css/japple?temp.documentID=366362&amp;temp.productID=154235&amp;temp.releaseID=361845&amp;temp.bucketID=126655&amp;PAGE=Document" source="CONFIRM">http://support.avaya.com/japple/css/japple?temp.documentID=366362&amp;temp.productID=154235&amp;temp.releaseID=361845&amp;temp.bucketID=126655&amp;PAGE=Document</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-208.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-208.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm</ref>
      <ref url="http://support.apple.com/kb/HT3757" source="CONFIRM">http://support.apple.com/kb/HT3757</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020521.1-1" source="SUNALERT">1020521</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-259989-1" source="SUNALERT">259989</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=1689&amp;release_id=662441" source="CONFIRM">http://sourceforge.net/project/shownotes.php?group_id=1689&amp;release_id=662441</ref>
      <ref url="http://sourceforge.net/mailarchive/message.php?msg_name=e56ccc8f0902181726i200f4bf0n20d919473ec409b7%40mail.gmail.com" source="MLIST">[png-mng-implement] 20090219 libpng-1.2.35 and libpng-1.0.43 fix security vulnerability</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.433952" source="SLACKWARE">SSA:2009-083-03</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.405420" source="SLACKWARE">SSA:2009-083-02</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-201209-25.xml" source="GENTOO">GLSA-201209-25</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200903-28.xml" source="GENTOO">GLSA-200903-28</ref>
      <ref url="http://secunia.com/advisories/36096" source="SECUNIA">36096</ref>
      <ref url="http://secunia.com/advisories/35386" source="SECUNIA">35386</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA">35379</ref>
      <ref url="http://secunia.com/advisories/35302" source="SECUNIA">35302</ref>
      <ref url="http://secunia.com/advisories/35258" source="SECUNIA">35258</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://secunia.com/advisories/34464" source="SECUNIA">34464</ref>
      <ref url="http://secunia.com/advisories/34462" source="SECUNIA">34462</ref>
      <ref url="http://secunia.com/advisories/34388" source="SECUNIA">34388</ref>
      <ref url="http://secunia.com/advisories/34324" source="SECUNIA">34324</ref>
      <ref url="http://secunia.com/advisories/34320" source="SECUNIA">34320</ref>
      <ref url="http://secunia.com/advisories/34272" source="SECUNIA">34272</ref>
      <ref url="http://secunia.com/advisories/34265" source="SECUNIA">34265</ref>
      <ref url="http://secunia.com/advisories/34210" source="SECUNIA">34210</ref>
      <ref url="http://secunia.com/advisories/34152" source="SECUNIA">34152</ref>
      <ref url="http://secunia.com/advisories/34145" source="SECUNIA">34145</ref>
      <ref url="http://secunia.com/advisories/34143" source="SECUNIA">34143</ref>
      <ref url="http://secunia.com/advisories/34140" source="SECUNIA">34140</ref>
      <ref url="http://secunia.com/advisories/34137" source="SECUNIA">34137</ref>
      <ref url="http://secunia.com/advisories/33976" source="SECUNIA" adv="1">33976</ref>
      <ref url="http://secunia.com/advisories/33970" source="SECUNIA" adv="1">33970</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6458" source="OVAL">oval:org.mitre.oval:def:6458</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10316" source="OVAL">oval:org.mitre.oval:def:10316</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2009/000062.html" source="MLIST">[security-announce] 20090820 VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00009.html" source="SUSE">SUSE-SA:2009:023</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00002.html" source="SUSE">SUSE-SA:2009:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html" source="SUSE">SUSE-SR:2009:005</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.html" source="APPLE">APPLE-SA-2009-08-05-1</ref>
      <ref url="http://downloads.sourceforge.net/libpng/libpng-1.2.34-ADVISORY.txt" source="CONFIRM">http://downloads.sourceforge.net/libpng/libpng-1.2.34-ADVISORY.txt</ref>
      <ref url="ftp://ftp.simplesystems.org/pub/png/src/libpng-1.2.34-ADVISORY.txt" source="CONFIRM" adv="1">ftp://ftp.simplesystems.org/pub/png/src/libpng-1.2.34-ADVISORY.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libpng" name="libpng">
        <vers num="0.89c"/>
        <vers num="0.95"/>
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.10" edition="beta1"/>
        <vers num="1.0.10" edition="rc1"/>
        <vers num="1.0.11" edition="beta1"/>
        <vers num="1.0.11" edition="beta2"/>
        <vers num="1.0.11" edition="beta3"/>
        <vers num="1.0.11" edition="rc1"/>
        <vers num="1.0.12" edition="beta1"/>
        <vers num="1.0.12" edition="rc1"/>
        <vers num="1.0.13"/>
        <vers num="1.0.14"/>
        <vers num="1.0.15" edition="rc1"/>
        <vers num="1.0.15" edition="rc2"/>
        <vers num="1.0.15" edition="rc3"/>
        <vers num="1.0.16"/>
        <vers num="1.0.17" edition="rc1"/>
        <vers num="1.0.18"/>
        <vers num="1.0.19" edition="rc1"/>
        <vers num="1.0.19" edition="rc2"/>
        <vers num="1.0.19" edition="rc3"/>
        <vers num="1.0.19" edition="rc5"/>
        <vers num="1.0.2"/>
        <vers num="1.0.20"/>
        <vers num="1.0.21" edition="rc1"/>
        <vers num="1.0.21" edition="rc2"/>
        <vers num="1.0.22" edition="rc1"/>
        <vers num="1.0.23" edition="rc1"/>
        <vers num="1.0.23" edition="rc2"/>
        <vers num="1.0.23" edition="rc3"/>
        <vers num="1.0.23" edition="rc4"/>
        <vers num="1.0.23" edition="rc5"/>
        <vers num="1.0.24" edition="rc1"/>
        <vers num="1.0.25" edition="rc1"/>
        <vers num="1.0.25" edition="rc2"/>
        <vers num="1.0.26"/>
        <vers num="1.0.27" edition="rc1"/>
        <vers num="1.0.27" edition="rc2"/>
        <vers num="1.0.27" edition="rc3"/>
        <vers num="1.0.27" edition="rc4"/>
        <vers num="1.0.27" edition="rc5"/>
        <vers num="1.0.27" edition="rc6"/>
        <vers num="1.0.28" edition="rc2"/>
        <vers num="1.0.28" edition="rc3"/>
        <vers num="1.0.28" edition="rc4"/>
        <vers num="1.0.28" edition="rc5"/>
        <vers num="1.0.28" edition="rc6"/>
        <vers num="1.0.29" edition="beta1"/>
        <vers num="1.0.29" edition="rc1"/>
        <vers num="1.0.29" edition="rc2"/>
        <vers num="1.0.29" edition="rc3"/>
        <vers num="1.0.3"/>
        <vers num="1.0.30"/>
        <vers num="1.0.31"/>
        <vers num="1.0.32"/>
        <vers num="1.0.33"/>
        <vers num="1.0.34"/>
        <vers num="1.0.35"/>
        <vers num="1.0.37"/>
        <vers num="1.0.38"/>
        <vers num="1.0.39"/>
        <vers num="1.0.40"/>
        <vers num="1.0.41"/>
        <vers prev="1" num="1.0.42"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6" edition="a"/>
        <vers num="1.0.6" edition="d"/>
        <vers num="1.0.6" edition="e"/>
        <vers num="1.0.6" edition="f"/>
        <vers num="1.0.6" edition="g"/>
        <vers num="1.0.6" edition="h"/>
        <vers num="1.0.6" edition="i"/>
        <vers num="1.0.6" edition="j"/>
        <vers num="1.0.7" edition="beta11"/>
        <vers num="1.0.7" edition="beta12"/>
        <vers num="1.0.7" edition="beta13"/>
        <vers num="1.0.7" edition="beta14"/>
        <vers num="1.0.7" edition="beta15"/>
        <vers num="1.0.7" edition="beta16"/>
        <vers num="1.0.7" edition="beta17"/>
        <vers num="1.0.7" edition="beta18"/>
        <vers num="1.0.7" edition="rc1"/>
        <vers num="1.0.7" edition="rc2"/>
        <vers num="1.0.8" edition="beta1"/>
        <vers num="1.0.8" edition="beta2"/>
        <vers num="1.0.8" edition="beta3"/>
        <vers num="1.0.8" edition="beta4"/>
        <vers num="1.0.8" edition="rc1"/>
        <vers num="1.0.9" edition="beta1"/>
        <vers num="1.0.9" edition="beta10"/>
        <vers num="1.0.9" edition="beta2"/>
        <vers num="1.0.9" edition="beta3"/>
        <vers num="1.0.9" edition="beta4"/>
        <vers num="1.0.9" edition="beta5"/>
        <vers num="1.0.9" edition="beta6"/>
        <vers num="1.0.9" edition="beta7"/>
        <vers num="1.0.9" edition="beta8"/>
        <vers num="1.0.9" edition="beta9"/>
        <vers num="1.0.9" edition="rc1"/>
        <vers num="1.0.9" edition="rc2"/>
        <vers num="1.2.0" edition="beta1"/>
        <vers num="1.2.0" edition="beta2"/>
        <vers num="1.2.0" edition="beta3"/>
        <vers num="1.2.0" edition="beta4"/>
        <vers num="1.2.0" edition="beta5"/>
        <vers num="1.2.0" edition="rc1"/>
        <vers num="1.2.1" edition="beta1"/>
        <vers num="1.2.1" edition="beta2"/>
        <vers num="1.2.1" edition="beta3"/>
        <vers num="1.2.1" edition="beta4"/>
        <vers num="1.2.1" edition="rc1"/>
        <vers num="1.2.1" edition="rc2"/>
        <vers num="1.2.10" edition="beta1"/>
        <vers num="1.2.10" edition="beta2"/>
        <vers num="1.2.10" edition="beta3"/>
        <vers num="1.2.10" edition="beta4"/>
        <vers num="1.2.10" edition="beta5"/>
        <vers num="1.2.10" edition="beta6"/>
        <vers num="1.2.10" edition="beta7"/>
        <vers num="1.2.10" edition="rc1"/>
        <vers num="1.2.10" edition="rc2"/>
        <vers num="1.2.10" edition="rc3"/>
        <vers num="1.2.11" edition="beta1"/>
        <vers num="1.2.11" edition="beta2"/>
        <vers num="1.2.11" edition="beta3"/>
        <vers num="1.2.11" edition="beta4"/>
        <vers num="1.2.11" edition="rc1"/>
        <vers num="1.2.11" edition="rc2"/>
        <vers num="1.2.11" edition="rc3"/>
        <vers num="1.2.11" edition="rc5"/>
        <vers num="1.2.13" edition="beta1"/>
        <vers num="1.2.13" edition="rc1"/>
        <vers num="1.2.13" edition="rc2"/>
        <vers num="1.2.14" edition="beta1"/>
        <vers num="1.2.14" edition="beta2"/>
        <vers num="1.2.14" edition="rc1"/>
        <vers num="1.2.15" edition="beta1"/>
        <vers num="1.2.15" edition="beta2"/>
        <vers num="1.2.15" edition="beta3"/>
        <vers num="1.2.15" edition="beta4"/>
        <vers num="1.2.15" edition="beta5"/>
        <vers num="1.2.15" edition="beta6"/>
        <vers num="1.2.15" edition="rc1"/>
        <vers num="1.2.15" edition="rc2"/>
        <vers num="1.2.15" edition="rc3"/>
        <vers num="1.2.15" edition="rc4"/>
        <vers num="1.2.15" edition="rc5"/>
        <vers num="1.2.16" edition="beta1"/>
        <vers num="1.2.16" edition="beta2"/>
        <vers num="1.2.16" edition="rc1"/>
        <vers num="1.2.17" edition="beta1"/>
        <vers num="1.2.17" edition="beta2"/>
        <vers num="1.2.17" edition="rc1"/>
        <vers num="1.2.17" edition="rc2"/>
        <vers num="1.2.17" edition="rc3"/>
        <vers num="1.2.17" edition="rc4"/>
        <vers num="1.2.18"/>
        <vers num="1.2.19" edition="beta1"/>
        <vers num="1.2.19" edition="beta10"/>
        <vers num="1.2.19" edition="beta11"/>
        <vers num="1.2.19" edition="beta12"/>
        <vers num="1.2.19" edition="beta13"/>
        <vers num="1.2.19" edition="beta14"/>
        <vers num="1.2.19" edition="beta15"/>
        <vers num="1.2.19" edition="beta16"/>
        <vers num="1.2.19" edition="beta17"/>
        <vers num="1.2.19" edition="beta18"/>
        <vers num="1.2.19" edition="beta19"/>
        <vers num="1.2.19" edition="beta2"/>
        <vers num="1.2.19" edition="beta20"/>
        <vers num="1.2.19" edition="beta21"/>
        <vers num="1.2.19" edition="beta22"/>
        <vers num="1.2.19" edition="beta23"/>
        <vers num="1.2.19" edition="beta24"/>
        <vers num="1.2.19" edition="beta25"/>
        <vers num="1.2.19" edition="beta26"/>
        <vers num="1.2.19" edition="beta27"/>
        <vers num="1.2.19" edition="beta28"/>
        <vers num="1.2.19" edition="beta29"/>
        <vers num="1.2.19" edition="beta3"/>
        <vers num="1.2.19" edition="beta30"/>
        <vers num="1.2.19" edition="beta31"/>
        <vers num="1.2.19" edition="beta32"/>
        <vers num="1.2.19" edition="beta33"/>
        <vers num="1.2.19" edition="beta4"/>
        <vers num="1.2.19" edition="beta5"/>
        <vers num="1.2.19" edition="beta6"/>
        <vers num="1.2.19" edition="beta7"/>
        <vers num="1.2.19" edition="beta8"/>
        <vers num="1.2.19" edition="beta9"/>
        <vers num="1.2.19" edition="rc1"/>
        <vers num="1.2.19" edition="rc2"/>
        <vers num="1.2.19" edition="rc3"/>
        <vers num="1.2.19" edition="rc4"/>
        <vers num="1.2.19" edition="rc5"/>
        <vers num="1.2.19" edition="rc6"/>
        <vers num="1.2.2" edition="beta1"/>
        <vers num="1.2.2" edition="beta2"/>
        <vers num="1.2.2" edition="beta3"/>
        <vers num="1.2.2" edition="beta4"/>
        <vers num="1.2.2" edition="beta5"/>
        <vers num="1.2.2" edition="beta6"/>
        <vers num="1.2.2" edition="rc1"/>
        <vers num="1.2.20" edition="rc1"/>
        <vers num="1.2.20" edition="rc2"/>
        <vers num="1.2.20" edition="rc3"/>
        <vers num="1.2.20" edition="rc4"/>
        <vers num="1.2.20" edition="rc5"/>
        <vers num="1.2.20" edition="rc6"/>
        <vers num="1.2.21" edition="beta1"/>
        <vers num="1.2.21" edition="beta2"/>
        <vers num="1.2.21" edition="rc1"/>
        <vers num="1.2.21" edition="rc2"/>
        <vers num="1.2.21" edition="rc3"/>
        <vers num="1.2.22" edition="beta1"/>
        <vers num="1.2.22" edition="beta2"/>
        <vers num="1.2.22" edition="beta3"/>
        <vers num="1.2.22" edition="beta4"/>
        <vers num="1.2.22" edition="rc1"/>
        <vers num="1.2.23"/>
        <vers num="1.2.24"/>
        <vers num="1.2.25" edition="beta03"/>
        <vers num="1.2.25" edition="beta04"/>
        <vers num="1.2.25" edition="beta05"/>
        <vers num="1.2.25" edition="beta06"/>
        <vers num="1.2.25" edition="rc01"/>
        <vers num="1.2.25" edition="rc02"/>
        <vers num="1.2.26" edition="beta01"/>
        <vers num="1.2.26" edition="beta02"/>
        <vers num="1.2.26" edition="beta03"/>
        <vers num="1.2.26" edition="beta04"/>
        <vers num="1.2.26" edition="beta05"/>
        <vers num="1.2.26" edition="beta06"/>
        <vers num="1.2.26" edition="rc01"/>
        <vers num="1.2.27"/>
        <vers num="1.2.28"/>
        <vers num="1.2.29"/>
        <vers num="1.2.3" edition="rc1"/>
        <vers num="1.2.3" edition="rc2"/>
        <vers num="1.2.3" edition="rc3"/>
        <vers num="1.2.3" edition="rc4"/>
        <vers num="1.2.3" edition="rc5"/>
        <vers num="1.2.3" edition="rc6"/>
        <vers num="1.2.30"/>
        <vers num="1.2.31"/>
        <vers num="1.2.32"/>
        <vers num="1.2.33"/>
        <vers num="1.2.34"/>
        <vers num="1.2.4" edition="beta1"/>
        <vers num="1.2.4" edition="beta2"/>
        <vers num="1.2.4" edition="beta3"/>
        <vers num="1.2.4" edition="rc1"/>
        <vers num="1.2.5" edition="beta1"/>
        <vers num="1.2.5" edition="beta2"/>
        <vers num="1.2.5" edition="beta3"/>
        <vers num="1.2.5" edition="rc1"/>
        <vers num="1.2.5" edition="rc2"/>
        <vers num="1.2.5" edition="rc3"/>
        <vers num="1.2.6" edition="beta1"/>
        <vers num="1.2.6" edition="beta2"/>
        <vers num="1.2.6" edition="beta3"/>
        <vers num="1.2.6" edition="beta4"/>
        <vers num="1.2.6" edition="rc1"/>
        <vers num="1.2.6" edition="rc2"/>
        <vers num="1.2.6" edition="rc3"/>
        <vers num="1.2.6" edition="rc4"/>
        <vers num="1.2.6" edition="rc5"/>
        <vers num="1.2.7" edition="beta1"/>
        <vers num="1.2.7" edition="beta2"/>
        <vers num="1.2.8" edition="beta1"/>
        <vers num="1.2.8" edition="beta2"/>
        <vers num="1.2.8" edition="beta3"/>
        <vers num="1.2.8" edition="beta4"/>
        <vers num="1.2.8" edition="beta5"/>
        <vers num="1.2.8" edition="rc1"/>
        <vers num="1.2.8" edition="rc2"/>
        <vers num="1.2.8" edition="rc3"/>
        <vers num="1.2.8" edition="rc4"/>
        <vers num="1.2.8" edition="rc5"/>
        <vers num="1.2.9" edition="beta1"/>
        <vers num="1.2.9" edition="beta10"/>
        <vers num="1.2.9" edition="beta2"/>
        <vers num="1.2.9" edition="beta3"/>
        <vers num="1.2.9" edition="beta4"/>
        <vers num="1.2.9" edition="beta5"/>
        <vers num="1.2.9" edition="beta6"/>
        <vers num="1.2.9" edition="beta7"/>
        <vers num="1.2.9" edition="beta8"/>
        <vers num="1.2.9" edition="beta9"/>
        <vers num="1.2.9" edition="rc1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0041" published="2009-01-14" name="CVE-2009-0041" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IAX2 in Asterisk Open Source 1.2.x before 1.2.31, 1.4.x before 1.4.23-rc4, and 1.6.x before 1.6.0.3-rc2; Business Edition A.x.x, B.x.x before B.2.5.7, C.1.x.x before C.1.10.4, and C.2.x.x before C.2.1.2.1; and s800i 1.2.x before 1.3.0 responds differently to a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.</descript>
      <descript source="nvd">Vendor Advisory: http://downloads.digium.com/pub/security/AST-2009-001.html</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33174" source="BID" patch="1">33174</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0063" source="VUPEN">ADV-2009-0063</ref>
      <ref url="http://www.securitytracker.com/id?1021549" source="SECTRACK">1021549</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/499884/100/0/threaded" source="BUGTRAQ">20090108 AST-2009-001: Information leak in IAX2 authentication</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1952" source="DEBIAN">DSA-1952</ref>
      <ref url="http://securityreason.com/securityalert/4910" source="SREASON">4910</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200905-01.xml" source="GENTOO">GLSA-200905-01</ref>
      <ref url="http://secunia.com/advisories/37677" source="SECUNIA">37677</ref>
      <ref url="http://secunia.com/advisories/34982" source="SECUNIA">34982</ref>
      <ref url="http://secunia.com/advisories/33453" source="SECUNIA">33453</ref>
      <ref url="http://downloads.digium.com/pub/security/AST-2009-001.html" source="CONFIRM">http://downloads.digium.com/pub/security/AST-2009-001.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asterisk" name="asterisk_business_edition">
        <vers num="a"/>
        <vers num="b.1.3.2"/>
        <vers num="b.1.3.3"/>
        <vers num="b.2.2.0"/>
        <vers num="b.2.2.1"/>
        <vers num="b.2.3.1"/>
        <vers num="b.2.3.2"/>
        <vers num="b.2.3.3"/>
        <vers num="b.2.3.4"/>
        <vers num="b.2.3.5"/>
        <vers num="b.2.3.6"/>
        <vers num="b.2.5.0"/>
        <vers num="b.2.5.1"/>
        <vers prev="1" num="b.2.5.2"/>
        <vers num="b.2.5.3"/>
        <vers prev="1" num="c.1.0" edition="beta7"/>
        <vers prev="1" num="c.1.0" edition="beta8"/>
      </prod>
      <prod vendor="asterisk" name="open_source">
        <vers num="1.2.0" edition="beta1"/>
        <vers num="1.2.0" edition="beta2"/>
        <vers num="1.2.0" edition="rc1"/>
        <vers num="1.2.0" edition="rc2"/>
        <vers num="1.2.0beta1"/>
        <vers num="1.2.0beta2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.10" edition="netsec"/>
        <vers num="1.2.11" edition="netsec"/>
        <vers num="1.2.12" edition="netsec"/>
        <vers num="1.2.12.1" edition="netsec"/>
        <vers num="1.2.13" edition="netsec"/>
        <vers num="1.2.14" edition="netsec"/>
        <vers num="1.2.15" edition="netsec"/>
        <vers num="1.2.16" edition="netsec"/>
        <vers num="1.2.17" edition="netsec"/>
        <vers num="1.2.18" edition="netsec"/>
        <vers num="1.2.19" edition="netsec"/>
        <vers num="1.2.2" edition="netsec"/>
        <vers num="1.2.20" edition="netsec"/>
        <vers num="1.2.21" edition="netsec"/>
        <vers num="1.2.21.1" edition="netsec"/>
        <vers num="1.2.22" edition="netsec"/>
        <vers num="1.2.23" edition="netsec"/>
        <vers num="1.2.24" edition="netsec"/>
        <vers num="1.2.25" edition="netsec"/>
        <vers num="1.2.26" edition="netsec"/>
        <vers num="1.2.26.1" edition="netsec"/>
        <vers num="1.2.26.2" edition="netsec"/>
        <vers num="1.2.27"/>
        <vers num="1.2.28"/>
        <vers num="1.2.29"/>
        <vers num="1.2.3" edition="netsec"/>
        <vers num="1.2.30"/>
        <vers num="1.2.30.2"/>
        <vers num="1.2.30.3"/>
        <vers prev="1" num="1.2.30.4"/>
        <vers num="1.4.0" edition="beta2"/>
        <vers num="1.4.0" edition="beta3"/>
        <vers num="1.4.0" edition="beta4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.10"/>
        <vers num="1.4.10.1"/>
        <vers num="1.4.11"/>
        <vers num="1.4.12"/>
        <vers num="1.4.12.1"/>
        <vers num="1.4.13"/>
        <vers num="1.4.14"/>
        <vers num="1.4.15"/>
        <vers num="1.4.16"/>
        <vers num="1.4.16.1"/>
        <vers num="1.4.16.2"/>
        <vers num="1.4.17"/>
        <vers num="1.4.18"/>
        <vers num="1.4.18.1"/>
        <vers num="1.4.19" edition="rc1"/>
        <vers num="1.4.19" edition="rc2"/>
        <vers num="1.4.19" edition="rc3"/>
        <vers num="1.4.19" edition="rc4"/>
        <vers num="1.4.19.1"/>
        <vers num="1.4.19.2"/>
        <vers num="1.4.2"/>
        <vers num="1.4.20" edition="rc1"/>
        <vers num="1.4.20" edition="rc2"/>
        <vers num="1.4.20" edition="rc3"/>
        <vers num="1.4.21" edition="rc1"/>
        <vers num="1.4.21" edition="rc2"/>
        <vers num="1.4.21.1"/>
        <vers num="1.4.21.2"/>
        <vers num="1.4.22" edition="rc3"/>
        <vers num="1.4.22" edition="rc4"/>
        <vers num="1.4.22.1"/>
        <vers num="1.4.22.2"/>
        <vers prev="1" num="1.4.23" edition="rc1"/>
        <vers prev="1" num="1.4.23" edition="rc2"/>
        <vers prev="1" num="1.4.23" edition="rc3"/>
        <vers num="1.4.3"/>
        <vers num="1.4.4"/>
        <vers num="1.4.5"/>
        <vers num="1.4.6"/>
        <vers num="1.4.7"/>
        <vers num="1.4.7.1"/>
        <vers num="1.4.8"/>
        <vers num="1.4.9"/>
        <vers num="1.4_revision_95946"/>
        <vers num="1.4beta"/>
        <vers num="1.6.0" edition="beta1"/>
        <vers num="1.6.0" edition="beta2"/>
        <vers num="1.6.0" edition="beta3"/>
        <vers num="1.6.0" edition="beta4"/>
        <vers num="1.6.0" edition="beta5"/>
        <vers num="1.6.0" edition="beta7"/>
        <vers num="1.6.0" edition="beta7.1"/>
        <vers num="1.6.0" edition="beta8"/>
        <vers num="1.6.0" edition="beta9"/>
        <vers num="1.6.0" edition="rc4"/>
        <vers num="1.6.0" edition="rc5"/>
        <vers num="1.6.0" edition="rc6"/>
        <vers num="1.6.0.1"/>
        <vers num="1.6.0.2"/>
        <vers prev="1" num="1.6.0.3" edition="rc1"/>
      </prod>
      <prod vendor="asterisk" name="s800i_appliance">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0042" published="2009-01-27" name="CVE-2009-0042" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the Arclib library (arclib.dll) before 7.3.0.15 in the CA Anti-Virus engine for CA Anti-Virus for the Enterprise 7.1, r8, and r8.1; Anti-Virus 2007 v8 and 2008; Internet Security Suite 2007 v3 and 2008; and other CA products allow remote attackers to bypass virus detection via a malformed archive file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48261" source="XF">ca-antivirus-engine-security-bypass(48261)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0270" source="VUPEN">ADV-2009-0270</ref>
      <ref url="http://www.securitytracker.com/id?1021639" source="SECTRACK">1021639</ref>
      <ref url="http://www.securityfocus.com/bid/33464" source="BID">33464</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500417/100/0/threaded" source="BUGTRAQ">20090127 CA20090126-01: CA Anti-Virus Engine Detection Evasion Multiple Vulnerabilities</ref>
      <ref url="http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197601" source="CONFIRM">http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197601</ref>
      <ref url="http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/26/ca20090126-01-ca-anti-virus-engine-detection-evasion-multiple-vulnerabilities.aspx" source="CONFIRM" adv="1">http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/26/ca20090126-01-ca-anti-virus-engine-detection-evasion-multiple-vulnerabilities.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="anti-spyware">
        <vers num="2007"/>
        <vers num="2008"/>
      </prod>
      <prod vendor="ca" name="anti-spyware_for_the_enterprise">
        <vers num="8.1"/>
        <vers num="r8"/>
      </prod>
      <prod vendor="ca" name="anti-virus">
        <vers num="2007" edition="8"/>
        <vers num="2008"/>
      </prod>
      <prod vendor="ca" name="anti-virus_for_the_enterprise">
        <vers num="7.1"/>
        <vers num="8.1"/>
        <vers num="r8"/>
      </prod>
      <prod vendor="ca" name="anti-virus_sdk">
        <vers num=""/>
      </prod>
      <prod vendor="ca" name="antivirus_gateway">
        <vers num="7.1"/>
      </prod>
      <prod vendor="ca" name="arcserve_backup">
        <vers num="r11.1" edition="_nil_"/>
        <vers num="r11.1" edition="_nil_:linux"/>
        <vers num="r11.1" edition="_nil_:windows"/>
        <vers num="r11.5_nil_" edition="linux"/>
        <vers num="r11.5_nil_" edition="windows"/>
        <vers num="r12.0_nil_" edition="windows"/>
      </prod>
      <prod vendor="ca" name="arcserve_client_agent">
        <vers num="_nil_" edition="_nil_"/>
        <vers num="_nil_" edition="_nil_:windows"/>
      </prod>
      <prod vendor="ca" name="common_services">
        <vers num="11"/>
        <vers num="11.1"/>
      </prod>
      <prod vendor="ca" name="etrust_ez_antivirus">
        <vers num="r6.1"/>
        <vers num="r7"/>
      </prod>
      <prod vendor="ca" name="etrust_intrusion_detection">
        <vers num="2.0" edition="sp1"/>
        <vers num="3.0" edition="sp1"/>
        <vers num="4.0"/>
      </prod>
      <prod vendor="ca" name="internet_security_suite_2007">
        <vers num="3"/>
      </prod>
      <prod vendor="ca" name="internet_security_suite_2008">
        <vers num=""/>
      </prod>
      <prod vendor="ca" name="internet_security_suite_plus_2008">
        <vers num=""/>
      </prod>
      <prod vendor="ca" name="network_and_systems_management">
        <vers num="r11"/>
        <vers num="r11.1"/>
        <vers num="r3.0"/>
        <vers num="r3.1"/>
      </prod>
      <prod vendor="ca" name="protection_suites">
        <vers num="r2"/>
        <vers num="r3"/>
        <vers num="r3.1"/>
      </prod>
      <prod vendor="ca" name="secure_content_manager">
        <vers num="8.0"/>
        <vers num="8.1"/>
      </prod>
      <prod vendor="ca" name="threat_manager_for_the_enterprise">
        <vers num="8.1"/>
        <vers num="r8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0043" published="2009-01-08" name="CVE-2009-0043" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The smmsnmpd service in CA Service Metric Analysis r11.0 through r11.1 SP1 and Service Level Management 3.5 does not properly restrict access, which allows remote attackers to execute arbitrary commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1" admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=196148" source="CONFIRM" patch="1">https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=196148</ref>
      <ref url="http://www.securityfocus.com/bid/33161" source="BID" patch="1">33161</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0053" source="VUPEN">ADV-2009-0053</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/499857/100/0/threaded" source="BUGTRAQ">20090107 CA20090107-01: CA Service Metric Analysis and CA Service Level Management smmsnmpd Arbitrary Command Execution Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/4887" source="SREASON">4887</ref>
      <ref url="http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/07.aspx" source="CONFIRM" adv="1">http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/07.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="service_level_management">
        <vers num="3.5"/>
      </prod>
      <prod vendor="ca" name="service_metric_analysis">
        <vers num="r11.0"/>
        <vers num="r11.1" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0046" published="2009-01-07" name="CVE-2009-0046" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sun GridEngine 5.3 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0045" source="VUPEN" adv="1">ADV-2009-0045</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/499827/100/0/threaded" source="BUGTRAQ">20090107 [oCERT-2008-016] Multiple OpenSSL signature verification API misuses</ref>
      <ref url="http://www.ocert.org/advisories/ocert-2008-016.html" source="MISC">http://www.ocert.org/advisories/ocert-2008-016.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="grid_engine">
        <vers prev="1" num="5.3" edition="beta1"/>
        <vers prev="1" num="5.3" edition="beta2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0047" published="2009-01-07" name="CVE-2009-0047" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Gale 0.99 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0046" source="VUPEN" adv="1">ADV-2009-0046</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/499827/100/0/threaded" source="BUGTRAQ">20090107 [oCERT-2008-016] Multiple OpenSSL signature verification API misuses</ref>
      <ref url="http://www.ocert.org/advisories/ocert-2008-016.html" source="MISC">http://www.ocert.org/advisories/ocert-2008-016.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gale" name="gale">
        <vers num="0.15"/>
        <vers num="0.15b"/>
        <vers num="0.15c"/>
        <vers num="0.16"/>
        <vers num="0.16a"/>
        <vers num="0.17"/>
        <vers num="0.17a"/>
        <vers num="0.18"/>
        <vers num="0.18b"/>
        <vers num="0.18c"/>
        <vers num="0.19"/>
        <vers num="0.19a"/>
        <vers num="0.19b"/>
        <vers num="0.20a"/>
        <vers num="0.21"/>
        <vers num="0.90a"/>
        <vers num="0.90b"/>
        <vers num="0.90c"/>
        <vers num="0.91"/>
        <vers num="0.91a"/>
        <vers num="0.91b"/>
        <vers prev="1" num="0.99"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0048" published="2009-01-07" name="CVE-2009-0048" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OpenEvidence 1.0.6 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0047" source="VUPEN" adv="1">ADV-2009-0047</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/499827/100/0/threaded" source="BUGTRAQ">20090107 [oCERT-2008-016] Multiple OpenSSL signature verification API misuses</ref>
      <ref url="http://www.ocert.org/advisories/ocert-2008-016.html" source="MISC">http://www.ocert.org/advisories/ocert-2008-016.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openevidence" name="openevidence">
        <vers num="1.0.5"/>
        <vers prev="1" num="1.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0049" published="2009-01-07" name="CVE-2009-0049" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Belgian eID middleware (eidlib) 2.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/499827/100/0/threaded" source="BUGTRAQ">20090107 [oCERT-2008-016] Multiple OpenSSL signature verification API misuses</ref>
      <ref url="http://www.ocert.org/advisories/ocert-2008-016.html" source="MISC">http://www.ocert.org/advisories/ocert-2008-016.html</ref>
      <ref url="http://secunia.com/advisories/34029" source="SECUNIA">34029</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html" source="SUSE">SUSE-SR:2009:005</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eid" name="eidlib">
        <vers prev="1" num="2.6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0050" published="2009-01-07" name="CVE-2009-0050" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47837" source="XF">openssl-dsa-verify-security-bypass(47837)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/499827/100/0/threaded" source="BUGTRAQ">20090107 [oCERT-2008-016] Multiple OpenSSL signature verification API misuses</ref>
      <ref url="http://www.ocert.org/advisories/ocert-2008-016.html" source="MISC">http://www.ocert.org/advisories/ocert-2008-016.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="entrouvert" name="lasso">
        <vers num="1.9.9.0"/>
        <vers num="2.0.0-1"/>
        <vers prev="1" num="2.2.1-0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0051" published="2009-01-07" name="CVE-2009-0051" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ZXID 0.29 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47837" source="XF">openssl-dsa-verify-security-bypass(47837)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/499827/100/0/threaded" source="BUGTRAQ">20090107 [oCERT-2008-016] Multiple OpenSSL signature verification API misuses</ref>
      <ref url="http://www.ocert.org/advisories/ocert-2008-016.html" source="MISC">http://www.ocert.org/advisories/ocert-2008-016.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zxid" name="zxid">
        <vers num="0.1"/>
        <vers num="0.10"/>
        <vers num="0.11"/>
        <vers num="0.12"/>
        <vers num="0.13"/>
        <vers num="0.14"/>
        <vers num="0.15"/>
        <vers num="0.16"/>
        <vers num="0.17"/>
        <vers num="0.18"/>
        <vers num="0.19"/>
        <vers num="0.2"/>
        <vers num="0.20"/>
        <vers num="0.21"/>
        <vers num="0.22"/>
        <vers num="0.25"/>
        <vers num="0.26"/>
        <vers num="0.27"/>
        <vers num="0.28"/>
        <vers prev="1" num="0.29"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0052" published="2009-11-12" name="CVE-2009-0052" modified="2012-01-05" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:S/C:N/I:N/A:C)" CVSS_score="5.5" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="5.1" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">The Atheros wireless driver, as used in Netgear WNDAP330 Wi-Fi access point with firmware 2.1.11 and other versions before 3.0.3 on the Atheros AR9160-BC1A chipset, and other products, allows remote authenticated users to cause a denial of service (device reboot or hang) and possibly execute arbitrary code via a truncated reserved management frame.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/54216" source="XF">netgear-wndap330-frame-dos(54216)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3212" source="VUPEN" adv="1">ADV-2009-3212</ref>
      <ref url="http://www.securityfocus.com/bid/36991" source="BID">36991</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507777/100/0/threaded" source="BUGTRAQ">20091110 Atheros Driver Reserved Frame Vulnerability</ref>
      <ref url="http://www.osvdb.org/59880" source="OSVDB">59880</ref>
      <ref url="http://secunia.com/advisories/37344" source="SECUNIA" adv="1">37344</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netgear" name="wndap330_firmware">
        <vers num="2.1.11"/>
      </prod>
      <prod vendor="atheros" name="ar9160-bc1a_chipset">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0053" published="2009-01-16" name="CVE-2009-0053" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">PXE Encryption in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to obtain the decryption key via unspecified vectors, related to a "logic error."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0140" source="VUPEN">ADV-2009-0140</ref>
      <ref url="http://www.securityfocus.com/bid/33268" source="BID">33268</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a5c4f7.shtml" source="CISCO" adv="1">20090114 IronPort Encryption Appliance / PostX and PXE Encryption Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1021593" source="SECTRACK">1021593</ref>
      <ref url="http://secunia.com/advisories/33479" source="SECUNIA">33479</ref>
      <ref url="http://osvdb.org/51395" source="OSVDB">51395</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ironport_encryption_appliance">
        <vers num="6.2.4"/>
        <vers num="6.2.4.1"/>
        <vers num="6.2.5"/>
        <vers num="6.2.6"/>
        <vers num="6.2.7"/>
        <vers num="6.2.7.1"/>
        <vers num="6.2.7.2"/>
        <vers num="6.2.7.3"/>
        <vers num="6.2.7.4"/>
        <vers num="6.2.7.5"/>
        <vers num="6.2.7.6"/>
        <vers num="6.3"/>
        <vers num="6.3.0.1"/>
        <vers num="6.3.0.2"/>
        <vers num="6.3.0.3"/>
        <vers num="6.5"/>
        <vers num="6.5.0.1"/>
      </prod>
      <prod vendor="cisco" name="ironport_postx">
        <vers num="6.2.1"/>
        <vers num="6.2.2"/>
        <vers num="6.2.2.1"/>
        <vers num="6.2.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0054" published="2009-01-16" name="CVE-2009-0054" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">PXE Encryption in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to capture credentials by tricking a user into reading a modified or crafted e-mail message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0140" source="VUPEN">ADV-2009-0140</ref>
      <ref url="http://www.securityfocus.com/bid/33268" source="BID">33268</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a5c4f7.shtml" source="CISCO" adv="1">20090114 IronPort Encryption Appliance / PostX and PXE Encryption Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1021593" source="SECTRACK">1021593</ref>
      <ref url="http://secunia.com/advisories/33479" source="SECUNIA">33479</ref>
      <ref url="http://osvdb.org/51396" source="OSVDB">51396</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ironport_encryption_appliance">
        <vers num="6.2.4"/>
        <vers num="6.2.4.1"/>
        <vers num="6.2.5"/>
        <vers num="6.2.6"/>
        <vers num="6.2.7"/>
        <vers num="6.2.7.1"/>
        <vers num="6.2.7.2"/>
        <vers num="6.2.7.3"/>
        <vers num="6.2.7.4"/>
        <vers num="6.2.7.5"/>
        <vers num="6.2.7.6"/>
        <vers num="6.3"/>
        <vers num="6.3.0.1"/>
        <vers num="6.3.0.2"/>
        <vers num="6.3.0.3"/>
        <vers num="6.5"/>
        <vers num="6.5.0.1"/>
      </prod>
      <prod vendor="cisco" name="ironport_postx">
        <vers num="6.2.1"/>
        <vers num="6.2.2"/>
        <vers num="6.2.2.1"/>
        <vers num="6.2.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0055" published="2009-01-16" name="CVE-2009-0055" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in the administration interface in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to modify appliance preferences as arbitrary users via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0140" source="VUPEN">ADV-2009-0140</ref>
      <ref url="http://www.securityfocus.com/bid/33268" source="BID">33268</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a5c4f7.shtml" source="CISCO" adv="1">20090114 IronPort Encryption Appliance / PostX and PXE Encryption Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1021594" source="SECTRACK">1021594</ref>
      <ref url="http://secunia.com/advisories/33479" source="SECUNIA">33479</ref>
      <ref url="http://osvdb.org/51397" source="OSVDB">51397</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ironport_encryption_appliance">
        <vers num="6.2.4"/>
        <vers num="6.2.4.1"/>
        <vers num="6.2.5"/>
        <vers num="6.2.6"/>
        <vers num="6.2.7"/>
        <vers num="6.2.7.1"/>
        <vers num="6.2.7.2"/>
        <vers num="6.2.7.3"/>
        <vers num="6.2.7.4"/>
        <vers num="6.2.7.5"/>
        <vers num="6.2.7.6"/>
        <vers num="6.3"/>
        <vers num="6.3.0.1"/>
        <vers num="6.3.0.2"/>
        <vers num="6.3.0.3"/>
        <vers num="6.5"/>
        <vers num="6.5.0.1"/>
      </prod>
      <prod vendor="cisco" name="ironport_postx">
        <vers num="6.2.1"/>
        <vers num="6.2.2"/>
        <vers num="6.2.2.1"/>
        <vers num="6.2.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0056" published="2009-01-16" name="CVE-2009-0056" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in the administration interface in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to execute commands and modify appliance preferences as arbitrary users via a logout action.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0140" source="VUPEN">ADV-2009-0140</ref>
      <ref url="http://www.securityfocus.com/bid/33268" source="BID">33268</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a5c4f7.shtml" source="CISCO" adv="1">20090114 IronPort Encryption Appliance / PostX and PXE Encryption Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1021594" source="SECTRACK">1021594</ref>
      <ref url="http://secunia.com/advisories/33479" source="SECUNIA">33479</ref>
      <ref url="http://osvdb.org/51398" source="OSVDB">51398</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ironport_encryption_appliance">
        <vers num="6.2.4"/>
        <vers num="6.2.4.1"/>
        <vers num="6.2.5"/>
        <vers num="6.2.6"/>
        <vers num="6.2.7"/>
        <vers num="6.2.7.1"/>
        <vers num="6.2.7.2"/>
        <vers num="6.2.7.3"/>
        <vers num="6.2.7.4"/>
        <vers num="6.2.7.5"/>
        <vers num="6.2.7.6"/>
        <vers num="6.3"/>
        <vers num="6.3.0.1"/>
        <vers num="6.3.0.2"/>
        <vers num="6.3.0.3"/>
        <vers num="6.5"/>
        <vers num="6.5.0.1"/>
      </prod>
      <prod vendor="cisco" name="ironport_postx">
        <vers num="6.2.1"/>
        <vers num="6.2.2"/>
        <vers num="6.2.2.1"/>
        <vers num="6.2.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0057" published="2009-01-22" name="CVE-2009-0057" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager 5.x before 5.1(3e) and 6.x before 6.1(3) allows remote attackers to cause a denial of service (voice service outage) by sending malformed input over a TCP session in which the "client terminates prematurely."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48139" source="XF">cucm-capf-dos-var1(48139)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0213" source="VUPEN">ADV-2009-0213</ref>
      <ref url="http://www.securitytracker.com/id?1021620" source="SECTRACK">1021620</ref>
      <ref url="http://www.securityfocus.com/bid/33379" source="BID">33379</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a61928.shtml" source="CISCO" adv="1">20090121 Cisco Unified Communications Manager CAPF Denial of Service Vulnerability</ref>
      <ref url="http://secunia.com/advisories/33588" source="SECUNIA" adv="1">33588</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="unified_communications_manager">
        <vers num="5.0"/>
        <vers num="5.0_1"/>
        <vers num="5.0_2"/>
        <vers num="5.0_3"/>
        <vers num="5.0_3a"/>
        <vers num="5.0_4"/>
        <vers num="5.0_4a"/>
        <vers num="5.0_4a_su1"/>
        <vers num="5.1" edition="(1)"/>
        <vers num="5.1" edition="(2)"/>
        <vers num="5.1" edition="(2a)"/>
        <vers num="5.1" edition="(2b)"/>
        <vers num="5.1" edition="(3a)"/>
        <vers num="5.1" edition="5.1(1)"/>
        <vers num="5.1" edition="5.1_(2a)"/>
        <vers num="5.1(1)"/>
        <vers num="5.1(2)"/>
        <vers num="5.1(3c)"/>
        <vers num="5.1.2"/>
        <vers num="5.1_(2a)"/>
        <vers num="5.1_1"/>
        <vers num="5.1_2"/>
        <vers num="5.1_2a"/>
        <vers num="5.1_2b"/>
        <vers num="5.1_3a"/>
        <vers num="6.0" edition="(1)"/>
        <vers num="6.0" edition="(1a)"/>
        <vers num="6.0_1"/>
        <vers num="6.0_1a"/>
        <vers num="6.1" edition="(1a)"/>
        <vers num="6.1(2)"/>
        <vers num="6.1.0"/>
        <vers num="6.1_1a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0058" published="2009-02-04" name="CVE-2009-0058" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="6.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.5" CVSS_base_score="6.1">
    <desc>
      <descript source="cve">The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.x before 5.2 allow remote attackers to cause a denial of service (web authentication outage or device reload) via unspecified network traffic, as demonstrated by a vulnerability scanner.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1021679" source="SECTRACK">1021679</ref>
      <ref url="http://www.securityfocus.com/bid/33608" source="BID">33608</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a6c1dd.shtml" source="CISCO" adv="1">20090204 Multiple Vulnerabilities in Cisco Wireless LAN Controllers</ref>
      <ref url="http://secunia.com/advisories/33749" source="SECUNIA">33749</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="4400_wireless_lan_controller">
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.2"/>
      </prod>
      <prod vendor="cisco" name="catalyst_3750_series_integrated_wireless_lan_controller">
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.2"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6500_series_integrated_wireless_lan_controller">
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.2"/>
      </prod>
      <prod vendor="cisco" name="catalyst_7600_series_wireless_lan_controller">
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.2"/>
      </prod>
      <prod vendor="cisco" name="wireless_lan_controller">
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0059" published="2009-02-04" name="CVE-2009-0059" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.2.x before 5.2.157.0 allow remote attackers to cause a denial of service (device reload) via a web authentication (aka WebAuth) session that includes a malformed POST request to login.html.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1021679" source="SECTRACK">1021679</ref>
      <ref url="http://www.securityfocus.com/bid/33608" source="BID">33608</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a6c1dd.shtml" source="CISCO" adv="1">20090204 Multiple Vulnerabilities in Cisco Wireless LAN Controllers</ref>
      <ref url="http://secunia.com/advisories/33749" source="SECUNIA">33749</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="4400_wireless_lan_controller">
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.2"/>
      </prod>
      <prod vendor="cisco" name="catalyst_3750_series_integrated_wireless_lan_controller">
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.2"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6500_series_integrated_wireless_lan_controller">
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.2"/>
      </prod>
      <prod vendor="cisco" name="catalyst_7600_series_wireless_lan_controller">
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.2"/>
      </prod>
      <prod vendor="cisco" name="wireless_lan_controller">
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0061" published="2009-02-04" name="CVE-2009-0061" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Wireless LAN Controller (WLC) TSEC driver in the Cisco 4400 WLC, Cisco Catalyst 6500 and 7600 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.x before 5.1 allows remote attackers to cause a denial of service (device crash or hang) via unknown IP packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1021679" source="SECTRACK">1021679</ref>
      <ref url="http://www.securityfocus.com/bid/33608" source="BID">33608</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a6c1dd.shtml" source="CISCO" adv="1">20090204 Multiple Vulnerabilities in Cisco Wireless LAN Controllers</ref>
      <ref url="http://secunia.com/advisories/33749" source="SECUNIA">33749</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="4400_wireless_lan_controller">
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
      </prod>
      <prod vendor="cisco" name="catalyst_3750_series_integrated_wireless_lan_controller">
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6500_series_integrated_wireless_lan_controller">
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
      </prod>
      <prod vendor="cisco" name="catalyst_7600_series_wireless_lan_controller">
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
      </prod>
      <prod vendor="cisco" name="wireless_lan_controller">
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0062" published="2009-02-04" name="CVE-2009-0062" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.2.173.0 allows remote authenticated users to gain privileges via unknown vectors, as demonstrated by escalation from the (1) Lobby Admin and (2) Local Management User privilege levels.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1021678" source="SECTRACK">1021678</ref>
      <ref url="http://www.securityfocus.com/bid/33608" source="BID">33608</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a6c1dd.shtml" source="CISCO" adv="1">20090204 Multiple Vulnerabilities in Cisco Wireless LAN Controllers</ref>
      <ref url="http://secunia.com/advisories/33749" source="SECUNIA">33749</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="catalyst_3750_series_integrated_wireless_lan_controller">
        <vers num="4.2"/>
        <vers num="4.2.173.0"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6500_wireless_services_modules">
        <vers num="4.2"/>
        <vers num="4.2.173.0"/>
      </prod>
      <prod vendor="cisco" name="wireless_lan_controller">
        <vers num="4.2"/>
        <vers num="4.2.173.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0063" published="2009-04-24" name="CVE-2009-0063" modified="2013-02-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Control Center in Symantec Brightmail Gateway Appliance before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1155" source="VUPEN" patch="1" adv="1">ADV-2009-1155</ref>
      <ref url="http://securitytracker.com/id?1022116" source="SECTRACK" patch="1">1022116</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50074" source="XF">brightmail-controlcenter-xss(50074)</ref>
      <ref url="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090423_01" source="CONFIRM">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090423_01</ref>
      <ref url="http://www.securityfocus.com/bid/34641" source="BID">34641</ref>
      <ref url="http://secunia.com/advisories/34885" source="SECUNIA">34885</ref>
      <ref url="http://osvdb.org/53944" source="OSVDB">53944</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="brightmail_gateway_appliance">
        <vers num="7.5"/>
        <vers num="7.6"/>
        <vers num="7.7"/>
        <vers prev="1" num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0064" published="2009-04-24" name="CVE-2009-0064" modified="2013-02-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the Control Center in Symantec Brightmail Gateway Appliance before 8.0.1 allow remote authenticated users to gain privileges, and possibly obtain sensitive information or hijack sessions of arbitrary users, via vectors involving (1) administrative scripts or (2) console functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1155" source="VUPEN" patch="1" adv="1">ADV-2009-1155</ref>
      <ref url="http://securitytracker.com/id?1022117" source="SECTRACK" patch="1">1022117</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50075" source="XF">brightmail-consolescripts-priv-escalation(50075)</ref>
      <ref url="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090423_01" source="CONFIRM">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090423_01</ref>
      <ref url="http://www.securityfocus.com/bid/34639" source="BID">34639</ref>
      <ref url="http://secunia.com/advisories/34885" source="SECUNIA">34885</ref>
      <ref url="http://osvdb.org/53945" source="OSVDB">53945</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="brightmail_gateway_appliance">
        <vers num="7.5"/>
        <vers num="7.6"/>
        <vers num="7.7"/>
        <vers prev="1" num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0065" published="2009-01-07" name="CVE-2009-0065" modified="2012-03-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in net/sctp/sm_statefuns.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.28-git8 allows remote attackers to have an unknown impact via an FWD-TSN (aka FORWARD-TSN) chunk with a large stream ID.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg01045.html" source="FEDORA">FEDORA-2009-0816</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=478800" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=478800</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2193" source="VUPEN">ADV-2009-2193</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0029" source="VUPEN">ADV-2009-0029</ref>
      <ref url="http://www.ubuntu.com/usn/usn-751-1" source="UBUNTU">USN-751-1</ref>
      <ref url="http://www.securitytracker.com/id?1022698" source="SECTRACK">1022698</ref>
      <ref url="http://www.securityfocus.com/bid/33113" source="BID">33113</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1055.html" source="REDHAT">RHSA-2009:1055</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0331.html" source="REDHAT">RHSA-2009:0331</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0053.html" source="REDHAT">RHSA-2009:0053</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/05/1" source="MLIST">[oss-security] 20090105 CVE request: kernel: sctp: memory overflow when FWD-TSN chunk is received with bad stream ID</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1794" source="DEBIAN">DSA-1794</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1787" source="DEBIAN">DSA-1787</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1749" source="DEBIAN">DSA-1749</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-114.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-114.htm</ref>
      <ref url="http://secunia.com/advisories/36191" source="SECUNIA">36191</ref>
      <ref url="http://secunia.com/advisories/35394" source="SECUNIA">35394</ref>
      <ref url="http://secunia.com/advisories/35390" source="SECUNIA">35390</ref>
      <ref url="http://secunia.com/advisories/35174" source="SECUNIA">35174</ref>
      <ref url="http://secunia.com/advisories/35011" source="SECUNIA">35011</ref>
      <ref url="http://secunia.com/advisories/34981" source="SECUNIA">34981</ref>
      <ref url="http://secunia.com/advisories/34762" source="SECUNIA">34762</ref>
      <ref url="http://secunia.com/advisories/34680" source="SECUNIA">34680</ref>
      <ref url="http://secunia.com/advisories/34394" source="SECUNIA">34394</ref>
      <ref url="http://secunia.com/advisories/34252" source="SECUNIA">34252</ref>
      <ref url="http://secunia.com/advisories/33858" source="SECUNIA">33858</ref>
      <ref url="http://secunia.com/advisories/33854" source="SECUNIA">33854</ref>
      <ref url="http://secunia.com/advisories/33674" source="SECUNIA">33674</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0264.html" source="REDHAT">RHSA-2009:0264</ref>
      <ref url="http://patchwork.ozlabs.org/patch/15024/" source="CONFIRM">http://patchwork.ozlabs.org/patch/15024/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10872" source="OVAL">oval:org.mitre.oval:def:10872</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE">SUSE-SA:2009:031</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE">SUSE-SA:2009:030</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.html" source="SUSE">SUSE-SA:2009:010</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01832118" source="HP">SSSRT090149</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01832118" source="HP">SSSRT090149</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=9fcb95a105758b81ef0131cd18e2db5149f13e95" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=9fcb95a105758b81ef0131cd18e2db5149f13e95</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.2.27"/>
        <vers num="2.4.36"/>
        <vers num="2.4.36.1"/>
        <vers num="2.4.36.2"/>
        <vers num="2.4.36.3"/>
        <vers num="2.4.36.4"/>
        <vers num="2.4.36.5"/>
        <vers num="2.4.36.6"/>
        <vers num="2.6"/>
        <vers num="2.6.18" edition="rc1"/>
        <vers num="2.6.18" edition="rc2"/>
        <vers num="2.6.18" edition="rc3"/>
        <vers num="2.6.18" edition="rc4"/>
        <vers num="2.6.18" edition="rc5"/>
        <vers num="2.6.18" edition="rc6"/>
        <vers num="2.6.18" edition="rc7"/>
        <vers num="2.6.19.4"/>
        <vers num="2.6.19.5"/>
        <vers num="2.6.19.6"/>
        <vers num="2.6.19.7"/>
        <vers num="2.6.20.16"/>
        <vers num="2.6.20.17"/>
        <vers num="2.6.20.18"/>
        <vers num="2.6.20.19"/>
        <vers num="2.6.20.20"/>
        <vers num="2.6.20.21"/>
        <vers num="2.6.21.5"/>
        <vers num="2.6.21.6"/>
        <vers num="2.6.21.7"/>
        <vers num="2.6.22"/>
        <vers num="2.6.22.1"/>
        <vers num="2.6.22.10"/>
        <vers num="2.6.22.11"/>
        <vers num="2.6.22.12"/>
        <vers num="2.6.22.13"/>
        <vers num="2.6.22.14"/>
        <vers num="2.6.22.15"/>
        <vers num="2.6.22.17"/>
        <vers num="2.6.22.18"/>
        <vers num="2.6.22.19"/>
        <vers num="2.6.22.2"/>
        <vers num="2.6.22.20"/>
        <vers num="2.6.22.21"/>
        <vers num="2.6.22.22"/>
        <vers num="2.6.22.8"/>
        <vers num="2.6.22.9"/>
        <vers num="2.6.22_rc1"/>
        <vers num="2.6.22_rc7"/>
        <vers num="2.6.23"/>
        <vers num="2.6.23.10"/>
        <vers num="2.6.23.11"/>
        <vers num="2.6.23.12"/>
        <vers num="2.6.23.13"/>
        <vers num="2.6.23.15"/>
        <vers num="2.6.23.16"/>
        <vers num="2.6.23.17"/>
        <vers num="2.6.23.8"/>
        <vers num="2.6.23.9"/>
        <vers num="2.6.23_rc1"/>
        <vers num="2.6.24"/>
        <vers num="2.6.24.1"/>
        <vers num="2.6.24.2"/>
        <vers num="2.6.24.3"/>
        <vers num="2.6.24.4"/>
        <vers num="2.6.24.5"/>
        <vers num="2.6.24.6"/>
        <vers num="2.6.24.7"/>
        <vers num="2.6.24_rc1"/>
        <vers num="2.6.24_rc4"/>
        <vers num="2.6.24_rc5"/>
        <vers num="2.6.25" edition=""/>
        <vers num="2.6.25" edition=":x86_64"/>
        <vers num="2.6.25.1" edition=""/>
        <vers num="2.6.25.1" edition=":x86_64"/>
        <vers num="2.6.25.10" edition=""/>
        <vers num="2.6.25.10" edition=":x86_64"/>
        <vers num="2.6.25.11" edition=""/>
        <vers num="2.6.25.11" edition=":x86_64"/>
        <vers num="2.6.25.12" edition=""/>
        <vers num="2.6.25.12" edition=":x86_64"/>
        <vers num="2.6.25.13"/>
        <vers num="2.6.25.14"/>
        <vers num="2.6.25.15"/>
        <vers num="2.6.25.16"/>
        <vers num="2.6.25.17"/>
        <vers num="2.6.25.2" edition=""/>
        <vers num="2.6.25.2" edition=":x86_64"/>
        <vers num="2.6.25.3" edition=""/>
        <vers num="2.6.25.3" edition=":x86_64"/>
        <vers num="2.6.25.4" edition=""/>
        <vers num="2.6.25.4" edition=":x86_64"/>
        <vers num="2.6.25.5" edition=""/>
        <vers num="2.6.25.5" edition=":x86_64"/>
        <vers num="2.6.25.6" edition=""/>
        <vers num="2.6.25.6" edition=":x86_64"/>
        <vers num="2.6.25.7" edition=""/>
        <vers num="2.6.25.7" edition=":x86_64"/>
        <vers num="2.6.25.8" edition=""/>
        <vers num="2.6.25.8" edition=":x86_64"/>
        <vers num="2.6.25.9" edition=""/>
        <vers num="2.6.25.9" edition=":x86_64"/>
        <vers num="2.6.26"/>
        <vers num="2.6.26.1"/>
        <vers num="2.6.26.2"/>
        <vers num="2.6.26.3"/>
        <vers num="2.6.26.4"/>
        <vers num="2.6.26.5"/>
        <vers prev="1" num="2.6.27"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0066" published="2009-01-07" name="CVE-2009-0066" modified="2009-01-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Intel system software for Trusted Execution Technology (TXT) allow attackers to bypass intended loader integrity protections, as demonstrated by exploitation of tboot.  NOTE: as of 20090107, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33119" source="BID">33119</ref>
      <ref url="http://theinvisiblethings.blogspot.com/2009/01/attacking-intel-trusted-execution.html" source="MISC">http://theinvisiblethings.blogspot.com/2009/01/attacking-intel-trusted-execution.html</ref>
      <ref url="http://invisiblethingslab.com/press/itl-press-2009-01.pdf" source="MISC">http://invisiblethingslab.com/press/itl-press-2009-01.pdf</ref>
      <ref url="http://blackhat.com/html/bh-dc-09/bh-dc-09-speakers.html#Wojtczuk" source="MISC">http://blackhat.com/html/bh-dc-09/bh-dc-09-speakers.html#Wojtczuk</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intel" name="trusted_execution_technology">
        <vers num="_nil_"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0068" published="2009-01-07" name="CVE-2009-0068" modified="2009-02-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Interaction error in xdg-open allows remote attackers to execute arbitrary code by sending a file with a dangerous MIME type but using a safe type that Firefox sends to xdg-open, which causes xdg-open to process the dangerous file type through automatic type detection, as demonstrated by overwriting the .desktop file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugs.freedesktop.org/show_bug.cgi?id=19377" source="MISC">https://bugs.freedesktop.org/show_bug.cgi?id=19377</ref>
      <ref url="http://www.securityfocus.com/bid/33137" source="BID">33137</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/06/1" source="MLIST">[oss-security] 20090106 Fwd: Using xdg-open in /etc/mailcap causes hole in Firefox (Demonstration/Exploit included)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freedesktop" name="xdg-utils">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0069" published="2009-01-07" name="CVE-2009-0069" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in the nfs4rename_persistent_fh function in the NFS 4 (aka NFSv4) client in the kernel in Sun Solaris 10 and OpenSolaris before snv_102 allows local users to cause a denial of service (recursive mutex_enter and panic) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-139466-02-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-139466-02-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/47750" source="XF">solaris-nfs4client-dos(47750)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0030" source="VUPEN">ADV-2009-0030</ref>
      <ref url="http://www.securitytracker.com/id?1021519" source="SECTRACK">1021519</ref>
      <ref url="http://www.securityfocus.com/bid/33128" source="BID">33128</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-248566-1" source="SUNALERT" adv="1">248566</ref>
      <ref url="http://secunia.com/advisories/33361" source="SECUNIA" adv="1">33361</ref>
      <ref url="http://mail.opensolaris.org/pipermail/onnv-notify/2008-October/015342.html" source="MLIST">[onnv-notify] 20081021 6300710 recursive mutex_enter in nfs4rename_persistent_fh()</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_01" edition=""/>
        <vers num="snv_01" edition=":sparc"/>
        <vers num="snv_01" edition=":x86"/>
        <vers num="snv_02" edition=""/>
        <vers num="snv_02" edition=":sparc"/>
        <vers num="snv_02" edition=":x86"/>
        <vers num="snv_03" edition=""/>
        <vers num="snv_03" edition=":x86"/>
        <vers num="snv_03" edition=":sparc"/>
        <vers num="snv_04" edition=""/>
        <vers num="snv_04" edition=":x86"/>
        <vers num="snv_04" edition=":sparc"/>
        <vers num="snv_05" edition=""/>
        <vers num="snv_05" edition=":sparc"/>
        <vers num="snv_05" edition=":x86"/>
        <vers num="snv_06" edition=""/>
        <vers num="snv_06" edition=":sparc"/>
        <vers num="snv_06" edition=":x86"/>
        <vers num="snv_07" edition=""/>
        <vers num="snv_07" edition=":sparc"/>
        <vers num="snv_07" edition=":x86"/>
        <vers num="snv_08" edition=""/>
        <vers num="snv_08" edition=":x86"/>
        <vers num="snv_08" edition=":sparc"/>
        <vers num="snv_09" edition=""/>
        <vers num="snv_09" edition=":x86"/>
        <vers num="snv_09" edition=":sparc"/>
        <vers num="snv_10" edition=""/>
        <vers num="snv_10" edition=":x86"/>
        <vers num="snv_10" edition=":sparc"/>
        <vers num="snv_100" edition=""/>
        <vers num="snv_100" edition=":sparc"/>
        <vers num="snv_100" edition=":x86"/>
        <vers prev="1" num="snv_101" edition=""/>
        <vers prev="1" num="snv_101" edition=":x86"/>
        <vers prev="1" num="snv_101" edition=":sparc"/>
        <vers num="snv_104" edition=""/>
        <vers num="snv_104" edition=":sparc"/>
        <vers num="snv_11" edition=""/>
        <vers num="snv_11" edition=":x86"/>
        <vers num="snv_11" edition=":sparc"/>
        <vers num="snv_12" edition=""/>
        <vers num="snv_12" edition=":x86"/>
        <vers num="snv_12" edition=":sparc"/>
        <vers num="snv_13" edition=""/>
        <vers num="snv_13" edition=":x86"/>
        <vers num="snv_13" edition=":sparc"/>
        <vers num="snv_14" edition=""/>
        <vers num="snv_14" edition=":sparc"/>
        <vers num="snv_14" edition=":x86"/>
        <vers num="snv_15" edition=""/>
        <vers num="snv_15" edition=":x86"/>
        <vers num="snv_15" edition=":sparc"/>
        <vers num="snv_16" edition=""/>
        <vers num="snv_16" edition=":sparc"/>
        <vers num="snv_16" edition=":x86"/>
        <vers num="snv_17" edition=""/>
        <vers num="snv_17" edition=":x86"/>
        <vers num="snv_17" edition=":sparc"/>
        <vers num="snv_18" edition=""/>
        <vers num="snv_18" edition=":x86"/>
        <vers num="snv_18" edition=":sparc"/>
        <vers num="snv_19" edition=""/>
        <vers num="snv_19" edition=":sparc"/>
        <vers num="snv_19" edition=":x86"/>
        <vers num="snv_20" edition=""/>
        <vers num="snv_20" edition=":x86"/>
        <vers num="snv_20" edition=":sparc"/>
        <vers num="snv_21" edition=""/>
        <vers num="snv_21" edition=":sparc"/>
        <vers num="snv_21" edition=":x86"/>
        <vers num="snv_22" edition=""/>
        <vers num="snv_22" edition=":sparc"/>
        <vers num="snv_22" edition=":x86"/>
        <vers num="snv_23" edition=""/>
        <vers num="snv_23" edition=":sparc"/>
        <vers num="snv_23" edition=":x86"/>
        <vers num="snv_24" edition=""/>
        <vers num="snv_24" edition=":sparc"/>
        <vers num="snv_24" edition=":x86"/>
        <vers num="snv_25" edition=""/>
        <vers num="snv_25" edition=":x86"/>
        <vers num="snv_25" edition=":sparc"/>
        <vers num="snv_26" edition=""/>
        <vers num="snv_26" edition=":x86"/>
        <vers num="snv_26" edition=":sparc"/>
        <vers num="snv_27" edition=""/>
        <vers num="snv_27" edition=":sparc"/>
        <vers num="snv_27" edition=":x86"/>
        <vers num="snv_28" edition=""/>
        <vers num="snv_28" edition=":x86"/>
        <vers num="snv_28" edition=":sparc"/>
        <vers num="snv_29" edition=""/>
        <vers num="snv_29" edition=":x86"/>
        <vers num="snv_29" edition=":sparc"/>
        <vers num="snv_30" edition=""/>
        <vers num="snv_30" edition=":sparc"/>
        <vers num="snv_30" edition=":x86"/>
        <vers num="snv_31" edition=""/>
        <vers num="snv_31" edition=":sparc"/>
        <vers num="snv_31" edition=":x86"/>
        <vers num="snv_32" edition=""/>
        <vers num="snv_32" edition=":x86"/>
        <vers num="snv_32" edition=":sparc"/>
        <vers num="snv_33" edition=""/>
        <vers num="snv_33" edition=":x86"/>
        <vers num="snv_33" edition=":sparc"/>
        <vers num="snv_34" edition=""/>
        <vers num="snv_34" edition=":sparc"/>
        <vers num="snv_34" edition=":x86"/>
        <vers num="snv_35" edition=""/>
        <vers num="snv_35" edition=":sparc"/>
        <vers num="snv_35" edition=":x86"/>
        <vers num="snv_36" edition=""/>
        <vers num="snv_36" edition=":x86"/>
        <vers num="snv_36" edition=":sparc"/>
        <vers num="snv_37" edition=""/>
        <vers num="snv_37" edition=":sparc"/>
        <vers num="snv_37" edition=":x86"/>
        <vers num="snv_38" edition=""/>
        <vers num="snv_38" edition=":sparc"/>
        <vers num="snv_38" edition=":x86"/>
        <vers num="snv_39" edition=""/>
        <vers num="snv_39" edition=":sparc"/>
        <vers num="snv_39" edition=":x86"/>
        <vers num="snv_40" edition=""/>
        <vers num="snv_40" edition=":sparc"/>
        <vers num="snv_40" edition=":x86"/>
        <vers num="snv_41" edition=""/>
        <vers num="snv_41" edition=":sparc"/>
        <vers num="snv_41" edition=":x86"/>
        <vers num="snv_42" edition=""/>
        <vers num="snv_42" edition=":x86"/>
        <vers num="snv_42" edition=":sparc"/>
        <vers num="snv_43" edition=""/>
        <vers num="snv_43" edition=":sparc"/>
        <vers num="snv_43" edition=":x86"/>
        <vers num="snv_44" edition=""/>
        <vers num="snv_44" edition=":x86"/>
        <vers num="snv_44" edition=":sparc"/>
        <vers num="snv_45" edition=""/>
        <vers num="snv_45" edition=":x86"/>
        <vers num="snv_45" edition=":sparc"/>
        <vers num="snv_46" edition=""/>
        <vers num="snv_46" edition=":x86"/>
        <vers num="snv_46" edition=":sparc"/>
        <vers num="snv_47" edition=""/>
        <vers num="snv_47" edition=":x86"/>
        <vers num="snv_47" edition=":sparc"/>
        <vers num="snv_48" edition=""/>
        <vers num="snv_48" edition=":sparc"/>
        <vers num="snv_48" edition=":x86"/>
        <vers num="snv_49" edition=""/>
        <vers num="snv_49" edition=":sparc"/>
        <vers num="snv_49" edition=":x86"/>
        <vers num="snv_50" edition=""/>
        <vers num="snv_50" edition=":sparc"/>
        <vers num="snv_50" edition=":x86"/>
        <vers num="snv_51" edition=""/>
        <vers num="snv_51" edition=":sparc"/>
        <vers num="snv_51" edition=":x86"/>
        <vers num="snv_52" edition=""/>
        <vers num="snv_52" edition=":sparc"/>
        <vers num="snv_52" edition=":x86"/>
        <vers num="snv_53" edition=""/>
        <vers num="snv_53" edition=":sparc"/>
        <vers num="snv_53" edition=":x86"/>
        <vers num="snv_54" edition=""/>
        <vers num="snv_54" edition=":x86"/>
        <vers num="snv_54" edition=":sparc"/>
        <vers num="snv_55" edition=""/>
        <vers num="snv_55" edition=":sparc"/>
        <vers num="snv_55" edition=":x86"/>
        <vers num="snv_56" edition=""/>
        <vers num="snv_56" edition=":x86"/>
        <vers num="snv_56" edition=":sparc"/>
        <vers num="snv_57" edition=""/>
        <vers num="snv_57" edition=":x86"/>
        <vers num="snv_57" edition=":sparc"/>
        <vers num="snv_58" edition=""/>
        <vers num="snv_58" edition=":sparc"/>
        <vers num="snv_58" edition=":x86"/>
        <vers num="snv_59" edition=""/>
        <vers num="snv_59" edition=":sparc"/>
        <vers num="snv_59" edition=":x86"/>
        <vers num="snv_60" edition=""/>
        <vers num="snv_60" edition=":x86"/>
        <vers num="snv_60" edition=":sparc"/>
        <vers num="snv_61" edition=""/>
        <vers num="snv_61" edition=":sparc"/>
        <vers num="snv_61" edition=":x86"/>
        <vers num="snv_62" edition=""/>
        <vers num="snv_62" edition=":x86"/>
        <vers num="snv_62" edition=":sparc"/>
        <vers num="snv_63" edition=""/>
        <vers num="snv_63" edition=":sparc"/>
        <vers num="snv_63" edition=":x86"/>
        <vers num="snv_64" edition=""/>
        <vers num="snv_64" edition=":x86"/>
        <vers num="snv_64" edition=":sparc"/>
        <vers num="snv_65" edition=""/>
        <vers num="snv_65" edition=":x86"/>
        <vers num="snv_65" edition=":sparc"/>
        <vers num="snv_66" edition=""/>
        <vers num="snv_66" edition=":x86"/>
        <vers num="snv_66" edition=":sparc"/>
        <vers num="snv_67" edition=""/>
        <vers num="snv_67" edition=":sparc"/>
        <vers num="snv_67" edition=":x86"/>
        <vers num="snv_68" edition=""/>
        <vers num="snv_68" edition=":x86"/>
        <vers num="snv_68" edition=":sparc"/>
        <vers num="snv_69" edition=""/>
        <vers num="snv_69" edition=":sparc"/>
        <vers num="snv_69" edition=":x86"/>
        <vers num="snv_70" edition=""/>
        <vers num="snv_70" edition=":sparc"/>
        <vers num="snv_70" edition=":x86"/>
        <vers num="snv_71" edition=""/>
        <vers num="snv_71" edition=":x86"/>
        <vers num="snv_71" edition=":sparc"/>
        <vers num="snv_72" edition=""/>
        <vers num="snv_72" edition=":x86"/>
        <vers num="snv_72" edition=":sparc"/>
        <vers num="snv_73" edition=""/>
        <vers num="snv_73" edition=":x86"/>
        <vers num="snv_73" edition=":sparc"/>
        <vers num="snv_74" edition=""/>
        <vers num="snv_74" edition=":sparc"/>
        <vers num="snv_74" edition=":x86"/>
        <vers num="snv_75" edition=""/>
        <vers num="snv_75" edition=":sparc"/>
        <vers num="snv_75" edition=":x86"/>
        <vers num="snv_76" edition=""/>
        <vers num="snv_76" edition=":x86"/>
        <vers num="snv_76" edition=":sparc"/>
        <vers num="snv_77" edition=""/>
        <vers num="snv_77" edition=":sparc"/>
        <vers num="snv_77" edition=":x86"/>
        <vers num="snv_78" edition=""/>
        <vers num="snv_78" edition=":sparc"/>
        <vers num="snv_78" edition=":x86"/>
        <vers num="snv_79" edition=""/>
        <vers num="snv_79" edition=":x86"/>
        <vers num="snv_79" edition=":sparc"/>
        <vers num="snv_80" edition=""/>
        <vers num="snv_80" edition=":x86"/>
        <vers num="snv_80" edition=":sparc"/>
        <vers num="snv_81" edition=""/>
        <vers num="snv_81" edition=":x86"/>
        <vers num="snv_81" edition=":sparc"/>
        <vers num="snv_82" edition=""/>
        <vers num="snv_82" edition=":x86"/>
        <vers num="snv_82" edition=":sparc"/>
        <vers num="snv_83" edition=""/>
        <vers num="snv_83" edition=":x86"/>
        <vers num="snv_83" edition=":sparc"/>
        <vers num="snv_84" edition=""/>
        <vers num="snv_84" edition=":x86"/>
        <vers num="snv_84" edition=":sparc"/>
        <vers num="snv_85" edition=""/>
        <vers num="snv_85" edition=":x86"/>
        <vers num="snv_85" edition=":sparc"/>
        <vers num="snv_86" edition=""/>
        <vers num="snv_86" edition=":sparc"/>
        <vers num="snv_86" edition=":x86"/>
        <vers num="snv_87" edition=""/>
        <vers num="snv_87" edition=":sparc"/>
        <vers num="snv_87" edition=":x86"/>
        <vers num="snv_88" edition=""/>
        <vers num="snv_88" edition=":x86"/>
        <vers num="snv_88" edition=":sparc"/>
        <vers num="snv_89" edition=""/>
        <vers num="snv_89" edition=":x86"/>
        <vers num="snv_89" edition=":sparc"/>
        <vers num="snv_90" edition=""/>
        <vers num="snv_90" edition=":sparc"/>
        <vers num="snv_90" edition=":x86"/>
        <vers num="snv_91" edition=""/>
        <vers num="snv_91" edition=":sparc"/>
        <vers num="snv_91" edition=":x86"/>
        <vers num="snv_92" edition=""/>
        <vers num="snv_92" edition=":sparc"/>
        <vers num="snv_92" edition=":x86"/>
        <vers num="snv_93" edition=""/>
        <vers num="snv_93" edition=":sparc"/>
        <vers num="snv_93" edition=":x86"/>
        <vers num="snv_94" edition=""/>
        <vers num="snv_94" edition=":x86"/>
        <vers num="snv_94" edition=":sparc"/>
        <vers num="snv_95" edition=""/>
        <vers num="snv_95" edition=":x86"/>
        <vers num="snv_95" edition=":sparc"/>
        <vers num="snv_96" edition=""/>
        <vers num="snv_96" edition=":sparc"/>
        <vers num="snv_96" edition=":x86"/>
        <vers num="snv_97" edition=""/>
        <vers num="snv_97" edition=":x86"/>
        <vers num="snv_97" edition=":sparc"/>
        <vers num="snv_98" edition=""/>
        <vers num="snv_98" edition=":sparc"/>
        <vers num="snv_98" edition=":x86"/>
        <vers num="snv_99" edition=""/>
        <vers num="snv_99" edition=":sparc"/>
        <vers num="snv_99" edition=":x86"/>
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10" edition=""/>
        <vers num="10" edition=":sparc"/>
        <vers num="10" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0070" published="2009-01-08" name="CVE-2009-0070" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer signedness error in Apple Safari allows remote attackers to read the contents of arbitrary memory locations, cause a denial of service (application crash), and probably have unspecified other impact via the array index of the arguments array in a JavaScript function, possibly a related issue to CVE-2008-2307.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48214" source="XF">safari-array-memory-disclosure(48214)</ref>
      <ref url="http://www.milw0rm.com/exploits/7673" source="MILW0RM">7673</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0071" published="2009-01-08" name="CVE-2009-0071" modified="2009-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a certain (a) replaceChild or (b) removeChild call, followed by a (1) queryCommandValue, (2) queryCommandState, or (3) queryCommandIndeterm call.  NOTE: it was later reported that 3.0.6 and 3.0.7 are also affected.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=472507" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=472507</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=456727" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=456727</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=448329" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=448329</ref>
      <ref url="http://www.securityfocus.com/bid/33154" source="BID">33154</ref>
      <ref url="http://www.milw0rm.com/exploits/8219" source="MILW0RM">8219</ref>
      <ref url="http://www.milw0rm.com/exploits/8091" source="MILW0RM">8091</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-01/0224.html" source="FULLDISC">20090107 Re: Firefox 3.0.5 remote vulnerability via queryCommandState</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-01/0223.html" source="FULLDISC">20090107 Re: Firefox 3.0.5 remote vulnerability via queryCommandState</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-01/0220.html" source="FULLDISC">20090107 Firefox 3.0.5 remote vulnerability via queryCommandState</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0" edition="alpha"/>
        <vers num="3.0" edition="beta2"/>
        <vers num="3.0" edition="beta5"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0072" published="2009-01-08" name="CVE-2009-0072" modified="2009-01-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6.0 through 8.0 beta2 allows remote attackers to cause a denial of service (application crash) via an onload=screen[""] attribute value in a BODY element.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47788" source="XF">ie-javascript-screen-dos(47788)</ref>
      <ref url="http://www.securityfocus.com/bid/33149" source="BID">33149</ref>
      <ref url="http://skypher.com/index.php/2009/01/07/msie-screen-null-ptr-dos-details/" source="MISC">http://skypher.com/index.php/2009/01/07/msie-screen-null-ptr-dos-details/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="6" edition="sp1"/>
        <vers num="6" edition="sp2"/>
        <vers num="7"/>
        <vers num="8" edition="beta1"/>
        <vers num="8" edition="beta2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0075" published="2009-02-10" name="CVE-2009-0075" modified="2010-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to CFunctionPointer and the appending of document objects, aka "Uninitialized Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-041A.html" source="CERT">TA09-041A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-002.mspx" source="MS" patch="1" adv="1">MS09-002</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-011/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-011/</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0389" source="VUPEN" adv="1">ADV-2009-0389</ref>
      <ref url="http://www.securityfocus.com/bid/33627" source="BID">33627</ref>
      <ref url="http://www.milw0rm.com/exploits/8082" source="MILW0RM">8082</ref>
      <ref url="http://www.milw0rm.com/exploits/8080" source="MILW0RM">8080</ref>
      <ref url="http://www.milw0rm.com/exploits/8079" source="MILW0RM">8079</ref>
      <ref url="http://www.milw0rm.com/exploits/8077" source="MILW0RM">8077</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6000" source="OVAL">oval:org.mitre.oval:def:6000</ref>
      <ref url="http://osvdb.org/51839" source="OSVDB">51839</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0076" published="2009-02-10" name="CVE-2009-0076" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the zoom style directive in conjunction with unspecified other directives in a malformed Cascading Style Sheets (CSS) stylesheet in a crafted HTML document, aka "CSS Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-041A.html" source="CERT">TA09-041A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-002.mspx" source="MS" patch="1" adv="1">MS09-002</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-012/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-012/</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0389" source="VUPEN">ADV-2009-0389</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6081" source="OVAL">oval:org.mitre.oval:def:6081</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0077" published="2009-04-15" name="CVE-2009-0077" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The firewall engine in Microsoft Forefront Threat Management Gateway, Medium Business Edition (TMG MBE); and Internet Security and Acceleration (ISA) Server 2004 SP3, 2006, 2006 Supportability Update, and 2006 SP1; does not properly manage the session state of web listeners, which allows remote attackers to cause a denial of service (many stale sessions) via crafted packets, aka "Web Proxy TCP State Limited Denial of Service Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-016.mspx" source="MS" patch="1" adv="1">MS09-016</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1030" source="VUPEN">ADV-2009-1030</ref>
      <ref url="http://www.securitytracker.com/id?1022045" source="SECTRACK">1022045</ref>
      <ref url="http://secunia.com/advisories/34687" source="SECUNIA">34687</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6068" source="OVAL">oval:org.mitre.oval:def:6068</ref>
      <ref url="http://osvdb.org/53636" source="OSVDB">53636</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="forefront_threat_management_gateway">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:medium_business"/>
      </prod>
      <prod vendor="microsoft" name="internet_security_and_acceleration_server">
        <vers num="2004" edition="sp3"/>
        <vers num="2004" edition="sp3:enterprise"/>
        <vers num="2004" edition="sp3:standard"/>
        <vers num="2006" edition="sp1"/>
        <vers num="2006" edition="supportability"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0078" published="2009-04-15" name="CVE-2009-0078" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Windows Management Instrumentation (WMI) provider in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows WMI Service Isolation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-012.mspx" source="MS" patch="1" adv="1">MS09-012</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1026" source="VUPEN">ADV-2009-1026</ref>
      <ref url="http://www.securitytracker.com/id?1022044" source="SECTRACK">1022044</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6193" source="OVAL">oval:org.mitre.oval:def:6193</ref>
      <ref url="http://osvdb.org/53666" source="OSVDB">53666</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:itanium"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":32_bit"/>
        <vers num="" edition=":itanium"/>
        <vers num="" edition=":x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
        <vers num="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":pro_x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:pro_x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0079" published="2009-04-15" name="CVE-2009-0079" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">The RPCSS service in Microsoft Windows XP SP2 and SP3 and Server 2003 SP1 and SP2 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows RPCSS Service Isolation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-012.mspx" source="MS" patch="1" adv="1">MS09-012</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1026" source="VUPEN">ADV-2009-1026</ref>
      <ref url="http://www.securitytracker.com/id?1022044" source="SECTRACK">1022044</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6147" source="OVAL">oval:org.mitre.oval:def:6147</ref>
      <ref url="http://osvdb.org/53667" source="OSVDB">53667</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:itanium"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":pro_x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:pro_x64"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0080" published="2009-04-15" name="CVE-2009-0080" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">The ThreadPool class in Windows Vista Gold and SP1, and Server 2008, does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by leveraging incorrect thread ACLs to access the resources of one of the processes, aka "Windows Thread Pool ACL Weakness Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-012.mspx" source="MS" patch="1" adv="1">MS09-012</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1026" source="VUPEN">ADV-2009-1026</ref>
      <ref url="http://www.securitytracker.com/id?1022044" source="SECTRACK">1022044</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6177" source="OVAL">oval:org.mitre.oval:def:6177</ref>
      <ref url="http://osvdb.org/53668" source="OSVDB">53668</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_server">
        <vers num="2008" edition="-"/>
        <vers num="2008" edition="-:x32"/>
        <vers num="2008" edition="-:x64"/>
        <vers num="2008" edition="-:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0081" published="2009-03-10" name="CVE-2009-0081" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The graphics device interface (GDI) implementation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate input received from user mode, which allows remote attackers to execute arbitrary code via a crafted (1) Windows Metafile (aka WMF) or (2) Enhanced Metafile (aka EMF) image file, aka "Windows Kernel Input Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-069A.html" source="CERT">TA09-069A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-006.mspx" source="MS" patch="1" adv="1">MS09-006</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0659" source="VUPEN">ADV-2009-0659</ref>
      <ref url="http://www.securitytracker.com/id?1021826" source="SECTRACK">1021826</ref>
      <ref url="http://www.securityfocus.com/bid/34012" source="BID">34012</ref>
      <ref url="http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=842987&amp;poid=" source="CONFIRM">http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=842987&amp;poid=</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-079.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-079.htm</ref>
      <ref url="http://secunia.com/advisories/34117" source="SECUNIA">34117</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6202" source="OVAL">oval:org.mitre.oval:def:6202</ref>
      <ref url="http://osvdb.org/52522" source="OSVDB">52522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:itanium"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium"/>
        <vers num="" edition=":x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
        <vers num="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0082" published="2009-03-10" name="CVE-2009-0082" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate handles, which allows local users to gain privileges via a crafted application that triggers unspecified "actions," aka "Windows Kernel Handle Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-069A.html" source="CERT">TA09-069A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0659" source="VUPEN">ADV-2009-0659</ref>
      <ref url="http://www.securitytracker.com/id?1021827" source="SECTRACK">1021827</ref>
      <ref url="http://www.securityfocus.com/bid/34027" source="BID">34027</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-006.mspx" source="MS">MS09-006</ref>
      <ref url="http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=842987&amp;poid=" source="CONFIRM">http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=842987&amp;poid=</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-079.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-079.htm</ref>
      <ref url="http://secunia.com/advisories/34117" source="SECUNIA">34117</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6036" source="OVAL">oval:org.mitre.oval:def:6036</ref>
      <ref url="http://osvdb.org/52523" source="OSVDB">52523</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:itanium"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium"/>
        <vers num="" edition=":x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
        <vers num="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0083" published="2009-03-10" name="CVE-2009-0083" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 does not properly handle invalid pointers, which allows local users to gain privileges via an application that triggers use of a crafted pointer, aka "Windows Kernel Invalid Pointer Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-069A.html" source="CERT">TA09-069A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-006.mspx" source="MS" patch="1" adv="1">MS09-006</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0659" source="VUPEN">ADV-2009-0659</ref>
      <ref url="http://www.securitytracker.com/id?1021827" source="SECTRACK">1021827</ref>
      <ref url="http://www.securityfocus.com/bid/34025" source="BID">34025</ref>
      <ref url="http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=842987&amp;poid=" source="CONFIRM">http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=842987&amp;poid=</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-079.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-079.htm</ref>
      <ref url="http://secunia.com/advisories/34117" source="SECUNIA">34117</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5440" source="OVAL">oval:org.mitre.oval:def:5440</ref>
      <ref url="http://osvdb.org/52524" source="OSVDB">52524</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:itanium"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium"/>
        <vers num="" edition=":x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
        <vers num="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0084" published="2009-04-15" name="CVE-2009-0084" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in DirectShow in Microsoft DirectX 8.1 and 9.0 allows remote attackers to execute arbitrary code via an MJPEG file or video stream with a malformed Huffman table, which triggers an exception that frees heap memory that is later accessed, aka "MJPEG Decompression Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-011.mspx" source="MS" patch="1" adv="1">MS09-011</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1025" source="VUPEN">ADV-2009-1025</ref>
      <ref url="http://www.securitytracker.com/id?1022040" source="SECTRACK">1022040</ref>
      <ref url="http://www.securityfocus.com/bid/34460" source="BID">34460</ref>
      <ref url="http://www.piotrbania.com/all/adv/ms-directx-mjpeg-adv.txt" source="MISC">http://www.piotrbania.com/all/adv/ms-directx-mjpeg-adv.txt</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-132.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-132.htm</ref>
      <ref url="http://secunia.com/advisories/34665" source="SECUNIA">34665</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5618" source="OVAL">oval:org.mitre.oval:def:5618</ref>
      <ref url="http://osvdb.org/53632" source="OSVDB">53632</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="directx">
        <vers num="8.1"/>
        <vers num="9.0"/>
        <vers num="9.0a"/>
        <vers num="9.0b"/>
        <vers num="9.0c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0085" published="2009-03-10" name="CVE-2009-0085" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:C/A:N)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The Secure Channel (aka SChannel) authentication component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, when certificate authentication is used, does not properly validate the client's key exchange data in Transport Layer Security (TLS) handshake messages, which allows remote attackers to spoof authentication by crafting a TLS packet based on knowledge of the certificate but not the private key, aka "SChannel Spoofing Vulnerability."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-069A.html" source="CERT">TA09-069A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-007.mspx" source="MS" patch="1" adv="1">MS09-007</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0660" source="VUPEN">ADV-2009-0660</ref>
      <ref url="http://www.securitytracker.com/id?1021828" source="SECTRACK">1021828</ref>
      <ref url="http://secunia.com/advisories/34215" source="SECUNIA">34215</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6011" source="OVAL">oval:org.mitre.oval:def:6011</ref>
      <ref url="http://osvdb.org/52521" source="OSVDB">52521</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:itanium"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium"/>
        <vers num="" edition=":x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
        <vers num="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0086" published="2009-04-15" name="CVE-2009-0086" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer underflow in Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote HTTP servers to execute arbitrary code via crafted parameter values in a response, related to error handling, aka "Windows HTTP Services Integer Underflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-013.mspx" source="MS" patch="1" adv="1">MS09-013</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1027" source="VUPEN">ADV-2009-1027</ref>
      <ref url="http://www.securitytracker.com/id?1022041" source="SECTRACK">1022041</ref>
      <ref url="http://www.securityfocus.com/bid/34435" source="BID">34435</ref>
      <ref url="http://secunia.com/advisories/34677" source="SECUNIA">34677</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6149" source="OVAL">oval:org.mitre.oval:def:6149</ref>
      <ref url="http://osvdb.org/53620" source="OSVDB">53620</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:itanium"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":32_bit"/>
        <vers num="" edition=":itanium"/>
        <vers num="" edition=":x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
        <vers num="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0087" published="2009-04-15" name="CVE-2009-0087" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Word 6 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and the Word 6 text converter in Microsoft Office Word 2000 SP3 and 2002 SP3; allows remote attackers to execute arbitrary code via a crafted Word 6 file that contains malformed data, aka "WordPad and Office Text Converter Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-010.mspx" source="MS" patch="1" adv="1">MS09-010</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1024" source="VUPEN">ADV-2009-1024</ref>
      <ref url="http://www.securitytracker.com/id?1022043" source="SECTRACK">1022043</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5799" source="OVAL">oval:org.mitre.oval:def:5799</ref>
      <ref url="http://osvdb.org/53662" source="OSVDB">53662</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_word">
        <vers num="2000" edition="sp3"/>
        <vers num="2002" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="windows">
        <vers num="2000" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="windows_server">
        <vers num="2003" edition="sp1"/>
        <vers num="2003" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="windows_srv">
        <vers num="2003" edition="-"/>
        <vers num="2003" edition="-:x64"/>
        <vers num="2003" edition="sp1"/>
        <vers num="2003" edition="sp1:itanium"/>
        <vers num="2003" edition="sp2"/>
        <vers num="2003" edition="sp2:x64"/>
        <vers num="2003" edition="sp2:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":pro_x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:pro_x64"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0088" published="2009-04-15" name="CVE-2009-0088" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The WordPerfect 6.x Converter (WPFT632.CNV, 1998.1.27.0) in Microsoft Office Word 2000 SP3 and Microsoft Office Converter Pack does not properly validate the length of an unspecified string, which allows remote attackers to execute arbitrary code via a crafted WordPerfect 6.x file, related to an unspecified counter and control structures on the stack, aka "Word 2000 WordPerfect 6.x Converter Stack Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-010.mspx" source="MS" patch="1" adv="1">MS09-010</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1024" source="VUPEN">ADV-2009-1024</ref>
      <ref url="http://www.securitytracker.com/id?1022043" source="SECTRACK">1022043</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5736" source="OVAL">oval:org.mitre.oval:def:5736</ref>
      <ref url="http://osvdb.org/53663" source="OSVDB">53663</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=782" source="IDEFENSE">20090414 Microsoft Word 2000 WordPerfect 6.x Converter Stack Corruption Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_converter_pack">
        <vers num="2003"/>
      </prod>
      <prod vendor="microsoft" name="office_word">
        <vers num="2000" edition="sp3"/>
        <vers num="2002" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:itanium"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":pro_x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:pro_x64"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0089" published="2009-04-15" name="CVE-2009-0089" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Vista Gold allows remote web servers to impersonate arbitrary https web sites by using DNS spoofing to "forward a connection" to a different https web site that has a valid certificate matching its own domain name, but not a certificate matching the domain name of the host requested by the user, aka "Windows HTTP Services Certificate Name Mismatch Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-013.mspx" source="MS" patch="1" adv="1">MS09-013</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1027" source="VUPEN">ADV-2009-1027</ref>
      <ref url="http://www.securitytracker.com/id?1022041" source="SECTRACK">1022041</ref>
      <ref url="http://www.securityfocus.com/bid/34437" source="BID">34437</ref>
      <ref url="http://secunia.com/advisories/34677" source="SECUNIA">34677</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6027" source="OVAL">oval:org.mitre.oval:def:6027</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:itanium"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium"/>
        <vers num="" edition=":x64"/>
        <vers num="" edition=":x32"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":pro_x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:pro_x64"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0090" published="2009-10-14" name="CVE-2009-0090" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unintended access to stack memory, and execute arbitrary code, via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Pointer Verification Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-286A.html" source="CERT">TA09-286A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-061.mspx" source="MS" patch="1" adv="1">MS09-061</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5716" source="OVAL">oval:org.mitre.oval:def:5716</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="1.0" edition="sp3"/>
        <vers num="1.1" edition="sp1"/>
        <vers num="2.0" edition="sp1"/>
        <vers num="2.0" edition="sp2"/>
        <vers num="3.5" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x32"/>
        <vers num="-" edition="-:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x32"/>
        <vers num="" edition=":itanium"/>
        <vers num="" edition=":x64"/>
        <vers num="" edition="r2"/>
        <vers num="" edition="r2:x64"/>
        <vers num="" edition="r2:itanium"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x32"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0091" published="2009-10-14" name="CVE-2009-0091" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Type Verification Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-286A.html" source="CERT">TA09-286A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-061.mspx" source="MS" patch="1" adv="1">MS09-061</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6451" source="OVAL">oval:org.mitre.oval:def:6451</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="1.0" edition="sp3"/>
        <vers num="1.1" edition="sp1"/>
        <vers num="2.0" edition="sp1"/>
        <vers num="2.0" edition="sp2"/>
        <vers num="3.5" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x32"/>
        <vers num="-" edition="-:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x32"/>
        <vers num="" edition=":itanium"/>
        <vers num="" edition=":x64"/>
        <vers num="" edition="r2"/>
        <vers num="" edition="r2:x64"/>
        <vers num="" edition="r2:itanium"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x32"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0093" published="2009-03-11" name="CVE-2009-0093" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not restrict registration of the "wpad" hostname, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) feature, and conduct man-in-the-middle attacks by spoofing a proxy server, via a Dynamic Update request for this hostname, aka "DNS Server Vulnerability in WPAD Registration Vulnerability," a related issue to CVE-2007-1692.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-069A.html" source="CERT">TA09-069A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-008.mspx" source="MS" patch="1" adv="1">MS09-008</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0661" source="VUPEN">ADV-2009-0661</ref>
      <ref url="http://www.securitytracker.com/id?1021830" source="SECTRACK">1021830</ref>
      <ref url="http://www.securityfocus.com/bid/33989" source="BID">33989</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-083.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-083.htm</ref>
      <ref url="http://secunia.com/advisories/34217" source="SECUNIA">34217</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6138" source="OVAL">oval:org.mitre.oval:def:6138</ref>
      <ref url="http://osvdb.org/52519" source="OSVDB">52519</ref>
      <ref url="http://blogs.technet.com/srd/archive/2009/03/13/ms09-008-dns-and-wins-server-security-update-in-more-detail.aspx" source="CONFIRM">http://blogs.technet.com/srd/archive/2009/03/13/ms09-008-dns-and-wins-server-security-update-in-more-detail.aspx</ref>
      <ref url="http://blog.ncircle.com/blogs/vert/archives/2009/03/successful_exploit_renders_mic.html" source="MISC">http://blog.ncircle.com/blogs/vert/archives/2009/03/successful_exploit_renders_mic.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:itanium"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0094" published="2009-03-11" name="CVE-2009-0094" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:P)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">The WINS server in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 does not restrict registration of the (1) "wpad" and (2) "isatap" NetBIOS names, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) and Intra-Site Automatic Tunnel Addressing Protocol (ISATAP) features, and conduct man-in-the-middle attacks by spoofing a proxy server or ISATAP route, by registering one of these names in the WINS database, aka "WPAD WINS Server Registration Vulnerability," a related issue to CVE-2007-1692.</descript>
      <descript source="nvd">Per: http://www.microsoft.com/technet/security/Bulletin/MS09-008.mspx

Mitigating Factors for WPAD WINS Server Registration Vulnerability - CVE-2009-0094

Mitigation refers to a setting, common configuration, or general best-practice, existing in a default state, that could reduce the severity of exploitation of a vulnerability. The following mitigating factors may be helpful in your situation.	

If WINS server already has WPAD and ISATAP registered than an attacker will not be able to register these as well.
</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-069A.html" source="CERT">TA09-069A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-008.mspx" source="MS" patch="1" adv="1">MS09-008</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0661" source="VUPEN">ADV-2009-0661</ref>
      <ref url="http://www.securitytracker.com/id?1021829" source="SECTRACK">1021829</ref>
      <ref url="http://www.securityfocus.com/bid/34013" source="BID">34013</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-083.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-083.htm</ref>
      <ref url="http://secunia.com/advisories/34217" source="SECUNIA">34217</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6117" source="OVAL">oval:org.mitre.oval:def:6117</ref>
      <ref url="http://osvdb.org/52520" source="OSVDB">52520</ref>
      <ref url="http://blogs.technet.com/srd/archive/2009/03/13/ms09-008-dns-and-wins-server-security-update-in-more-detail.aspx" source="CONFIRM">http://blogs.technet.com/srd/archive/2009/03/13/ms09-008-dns-and-wins-server-security-update-in-more-detail.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:itanium"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0095" published="2009-02-10" name="CVE-2009-0095" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly validate object data in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Memory Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-041A.html" source="CERT">TA09-041A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-005.mspx" source="MS" patch="1" adv="1">MS09-005</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0391" source="VUPEN">ADV-2009-0391</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6179" source="OVAL">oval:org.mitre.oval:def:6179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visio">
        <vers num="2002" edition="sp2"/>
        <vers num="2003" edition="sp3"/>
        <vers num="2007" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0096" published="2009-02-10" name="CVE-2009-0096" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly perform memory copy operations for object data, which allows remote attackers to execute arbitrary code via a crafted Visio document, aka "Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-041A.html" source="CERT">TA09-041A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0391" source="VUPEN">ADV-2009-0391</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-005.mspx" source="MS" adv="1">MS09-005</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6172" source="OVAL">oval:org.mitre.oval:def:6172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visio">
        <vers num="2002" edition="sp2"/>
        <vers num="2003" edition="sp3"/>
        <vers num="2007" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0097" published="2009-02-10" name="CVE-2009-0097" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office Visio 2002 SP2 and 2003 SP3 does not properly validate memory allocation for Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-041A.html" source="CERT">TA09-041A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-005.mspx" source="MS" patch="1" adv="1">MS09-005</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0391" source="VUPEN">ADV-2009-0391</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6188" source="OVAL">oval:org.mitre.oval:def:6188</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visio">
        <vers num="2002" edition="sp2"/>
        <vers num="2003" edition="sp3"/>
        <vers num="2007" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0098" published="2009-02-10" name="CVE-2009-0098" modified="2009-03-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1 do not properly interpret Transport Neutral Encapsulation (TNEF) properties, which allows remote attackers to execute arbitrary code via a crafted TNEF message, aka "Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-041A.html" source="CERT">TA09-041A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-003.mspx" source="MS" patch="1" adv="1">MS09-003</ref>
      <ref url="http://secunia.com/advisories/33838" source="SECUNIA">33838</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6114" source="OVAL">oval:org.mitre.oval:def:6114</ref>
      <ref url="http://osvdb.org/51837" source="OSVDB">51837</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp2"/>
        <vers num="2007" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0099" published="2009-02-10" name="CVE-2009-0099" modified="2009-03-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Electronic Messaging System Microsoft Data Base (EMSMDB32) provider in Microsoft Exchange 2000 Server SP3 and Exchange Server 2003 SP2, as used in Exchange System Attendant, allows remote attackers to cause a denial of service (application outage) via a malformed MAPI command, aka "Literal Processing Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-041A.html" source="CERT">TA09-041A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-003.mspx" source="MS" patch="1" adv="1">MS09-003</ref>
      <ref url="http://secunia.com/advisories/33838" source="SECUNIA">33838</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6159" source="OVAL">oval:org.mitre.oval:def:6159</ref>
      <ref url="http://osvdb.org/51838" source="OSVDB">51838</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp2"/>
        <vers num="2007" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0100" published="2009-04-15" name="CVE-2009-0100" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel in Microsoft Office 2004 and 2008 for Mac; Microsoft Office Excel Viewer and Excel Viewer 2003 SP3; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 do not properly parse the Excel spreadsheet file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that contains a malformed object with "an offset and a two-byte value" that trigger a memory calculation error, aka "Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-009.mspx" source="MS" patch="1" adv="1">MS09-009</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1023" source="VUPEN">ADV-2009-1023</ref>
      <ref url="http://www.securitytracker.com/id?1022039" source="SECTRACK">1022039</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502696/100/0/threaded" source="BUGTRAQ">20090415 Microsoft Office Excel Remote Memory Corruption Vulnerability</ref>
      <ref url="http://www.fortiguardcenter.com/advisory/FGA-2009-16.html" source="MISC">http://www.fortiguardcenter.com/advisory/FGA-2009-16.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6043" source="OVAL">oval:org.mitre.oval:def:6043</ref>
      <ref url="http://osvdb.org/53665" source="OSVDB">53665</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
        <vers num="2008" edition=""/>
        <vers num="2008" edition=":mac"/>
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack_for_word_excel_ppt_2007">
        <vers num="" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="office_excel">
        <vers num="2000" edition="sp3"/>
        <vers num="2002" edition="sp3"/>
        <vers num="2003" edition="sp3"/>
        <vers num="2007" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="office_excel_viewer">
        <vers num="2003" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0102" published="2009-12-09" name="CVE-2009-0102" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attackers to execute arbitrary code via a malformed file, aka "Project Memory Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-342A.html" source="CERT">TA09-342A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-074.mspx" source="MS" patch="1" adv="1">MS09-074</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6298" source="OVAL">oval:org.mitre.oval:def:6298</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_project">
        <vers num="2007" edition="sp1"/>
        <vers num="2007" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="project_portfolio_server">
        <vers num="2007" edition="sp1"/>
        <vers num="2007" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="project_server">
        <vers num="2003" edition="sp3"/>
        <vers num="2007" edition="sp1"/>
        <vers num="2007" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0103" published="2009-01-09" name="CVE-2009-0103" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) apps_path[plug] parameter to plugin/gateway/gnokii/init.php, the (2) apps_path[themes] parameter to plugin/themes/default/init.php, and the (3) apps_path[libs] parameter to lib/function.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33138" source="BID">33138</ref>
      <ref url="http://www.milw0rm.com/exploits/7687" source="MILW0RM">7687</ref>
      <ref url="http://securityreason.com/securityalert/4888" source="SREASON">4888</ref>
      <ref url="http://secunia.com/advisories/33386" source="SECUNIA" adv="1">33386</ref>
    </refs>
    <vuln_soft>
      <prod vendor="playsms" name="playsms">
        <vers num="0.9.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0104" published="2009-01-09" name="CVE-2009-0104" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in EZpack 4.2b2 allows remote attackers to execute arbitrary SQL commands via the qType parameter in a webboard prog action.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33131" source="BID">33131</ref>
      <ref url="http://www.milw0rm.com/exploits/7680" source="MILW0RM">7680</ref>
      <ref url="http://securityreason.com/securityalert/4890" source="SREASON">4890</ref>
    </refs>
    <vuln_soft>
      <prod vendor="se-ed" name="ezpack">
        <vers num="4.2" edition="beta2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0105" published="2009-01-09" name="CVE-2009-0105" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in EZpack 4.2b2 allows remote attackers to inject arbitrary web script or HTML via the mdfd parameter in a prog action.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33131" source="BID">33131</ref>
      <ref url="http://www.milw0rm.com/exploits/7680" source="MILW0RM">7680</ref>
      <ref url="http://securityreason.com/securityalert/4890" source="SREASON">4890</ref>
    </refs>
    <vuln_soft>
      <prod vendor="se-ed" name="ezpack">
        <vers num="4.2" edition="beta2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0106" published="2009-01-09" name="CVE-2009-0106" modified="2009-04-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in profile.php in PHPAuctions (aka PHPAuctionSystem) allows remote attackers to execute arbitrary SQL commands via the user_id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/43264" source="XF">phpauctions-profile-sql-injection(43264)</ref>
      <ref url="http://www.securityfocus.com/bid/33115" source="BID">33115</ref>
      <ref url="http://secunia.com/advisories/33331" source="SECUNIA" adv="1">33331</ref>
      <ref url="http://osvdb.org/51144" source="OSVDB">51144</ref>
      <ref url="http://milw0rm.com/exploits/7672" source="MILW0RM">7672</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpauctions" name="phpauctions">
        <vers num="_nil_"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0107" published="2009-01-09" name="CVE-2009-0107" modified="2009-01-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in profile.php in PHPAuctions (aka PHPAuctionSystem) allows remote attackers to inject arbitrary web script or HTML via the user_id parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33115" source="BID">33115</ref>
      <ref url="http://secunia.com/advisories/33331" source="SECUNIA" adv="1">33331</ref>
      <ref url="http://osvdb.org/51145" source="OSVDB">51145</ref>
      <ref url="http://milw0rm.com/exploits/7672" source="MILW0RM">7672</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpauctions" name="phpauctions">
        <vers num="_nil_"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0108" published="2009-01-09" name="CVE-2009-0108" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHPAuctions (aka PHPAuctionSystem) allows remote attackers to bypass authentication and gain administrative access via modified (1) PHPAUCTION_RM_ID, (2) PHPAUCTION_RM_NAME, (3) PHPAUCTION_RM_USERNAME, and (4) PHPAUCTION_RM_EMAIL cookies.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33120" source="BID">33120</ref>
      <ref url="http://www.milw0rm.com/exploits/7674" source="MILW0RM">7674</ref>
      <ref url="http://securityreason.com/securityalert/4891" source="SREASON">4891</ref>
      <ref url="http://secunia.com/advisories/33331" source="SECUNIA" adv="1">33331</ref>
      <ref url="http://osvdb.org/51146" source="OSVDB">51146</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpauctions" name="phpauctions">
        <vers num="_nil_"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0109" published="2009-01-09" name="CVE-2009-0109" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33132" source="BID">33132</ref>
      <ref url="http://www.milw0rm.com/exploits/7682" source="MILW0RM">7682</ref>
      <ref url="http://securityreason.com/securityalert/4892" source="SREASON">4892</ref>
      <ref url="http://secunia.com/advisories/33395" source="SECUNIA" adv="1">33395</ref>
    </refs>
    <vuln_soft>
      <prod vendor="riotpix" name="riotpix">
        <vers num=".05"/>
        <vers num="0.5"/>
        <vers num="0.51" edition="beta"/>
        <vers num="0.52"/>
        <vers num="0.60"/>
        <vers prev="1" num="0.61"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0110" published="2009-01-09" name="CVE-2009-0110" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in read.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL commands via the forumid parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33129" source="BID">33129</ref>
      <ref url="http://www.milw0rm.com/exploits/7679" source="MILW0RM">7679</ref>
      <ref url="http://securityreason.com/securityalert/4893" source="SREASON">4893</ref>
      <ref url="http://secunia.com/advisories/33395" source="SECUNIA" adv="1">33395</ref>
    </refs>
    <vuln_soft>
      <prod vendor="riotpix" name="riotpix">
        <vers num=".05"/>
        <vers num="0.5"/>
        <vers num="0.51" edition="beta"/>
        <vers num="0.52"/>
        <vers num="0.60"/>
        <vers prev="1" num="0.61"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0111" published="2009-01-09" name="CVE-2009-0111" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33135" source="BID">33135</ref>
      <ref url="http://www.milw0rm.com/exploits/7683" source="MILW0RM">7683</ref>
      <ref url="http://securityreason.com/securityalert/4894" source="SREASON">4894</ref>
      <ref url="http://secunia.com/advisories/33393" source="SECUNIA" adv="1">33393</ref>
    </refs>
    <vuln_soft>
      <prod vendor="goople_cms" name="goople_cms">
        <vers prev="1" num="1.8.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0112" published="2009-01-09" name="CVE-2009-0112" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in admin/agent_edit.asp in PollPro 3.0 allows remote attackers to create or modify accounts as administrators via the username, password, and name parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47754" source="XF">pollpro-unspecified-csrf(47754)</ref>
      <ref url="http://securityreason.com/securityalert/4895" source="SREASON">4895</ref>
      <ref url="http://secunia.com/advisories/33319" source="SECUNIA" adv="1">33319</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=123117044713213&amp;w=2" source="BUGTRAQ">20090103 PollPro 3.0 XSRF VuLn</ref>
    </refs>
    <vuln_soft>
      <prod vendor="expinion" name="poll_pro">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0113" published="2009-01-09" name="CVE-2009-0113" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in attachmentlibrary.php in the XStandard component for Joomla! 1.5.8 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the X_CMS_LIBRARY_PATH HTTP header.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33143" source="BID">33143</ref>
      <ref url="http://www.milw0rm.com/exploits/7691" source="MILW0RM">7691</ref>
      <ref url="http://securityreason.com/securityalert/4896" source="SREASON">4896</ref>
      <ref url="http://secunia.com/advisories/33377" source="SECUNIA" adv="1">33377</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="xstandard">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0114" published="2009-02-26" name="CVE-2009-0114" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Settings Manager in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87, and possibly other versions, allows remote attackers to trick a user into visiting an arbitrary URL via unknown vectors, related to "a potential Clickjacking issue variant."</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0513" source="VUPEN" patch="1">ADV-2009-0513</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-01.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-01.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48902" source="XF">flash-settings-manager-click-hijacking(48902)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0743" source="VUPEN">ADV-2009-0743</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-254909-1" source="SUNALERT">254909</ref>
      <ref url="http://securitytracker.com/id?1021751" source="SECTRACK">1021751</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200903-23.xml" source="GENTOO">GLSA-200903-23</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://secunia.com/advisories/34293" source="SECUNIA">34293</ref>
      <ref url="http://secunia.com/advisories/34226" source="SECUNIA">34226</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6662" source="OVAL">oval:org.mitre.oval:def:6662</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
      <ref url="http://isc.sans.org/diary.html?storyid=5929" source="MISC">http://isc.sans.org/diary.html?storyid=5929</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="air">
        <vers num="1.5"/>
      </prod>
      <prod vendor="adobe" name="flash_player">
        <vers num="10.0.0.584"/>
        <vers num="10.0.12.10"/>
        <vers prev="1" num="10.0.12.36"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.25"/>
        <vers num="7.0.63" edition=""/>
        <vers num="7.0.63" edition=":linux"/>
        <vers num="7.0.69.0"/>
        <vers num="7.0.70.0"/>
        <vers num="7.1"/>
        <vers num="7.1.1"/>
        <vers num="7.2"/>
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":pro"/>
        <vers num="8.0" edition=":basic"/>
        <vers num="8.0.24.0"/>
        <vers num="8.0.34.0"/>
        <vers num="8.0.35.0"/>
        <vers num="8.0.39.0"/>
        <vers num="9.0.112.0"/>
        <vers num="9.0.114.0"/>
        <vers num="9.0.115.0"/>
        <vers num="9.0.124.0"/>
        <vers num="9.0.16"/>
        <vers num="9.0.20"/>
        <vers num="9.0.20.0"/>
        <vers num="9.0.28"/>
        <vers num="9.0.28.0"/>
        <vers num="9.0.31.0"/>
        <vers num="9.0.45.0"/>
        <vers num="9.0.47.0"/>
        <vers num="9.0.48.0"/>
        <vers num="cs3" edition=""/>
        <vers num="cs3" edition=":pro"/>
        <vers num="cs4" edition=""/>
        <vers num="cs4" edition=":pro"/>
      </prod>
      <prod vendor="adobe" name="flash_player_for_linux">
        <vers prev="1" num="10.0.15.3"/>
      </prod>
      <prod vendor="adobe" name="flex">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0115" published="2009-03-30" name="CVE-2009-0115" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send arbitrary commands to the multipath daemon.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00236.html" source="FEDORA">FEDORA-2009-3453</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00231.html" source="FEDORA">FEDORA-2009-3449</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0528" source="VUPEN">ADV-2010-0528</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1767" source="DEBIAN">DSA-1767</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-128.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-128.htm</ref>
      <ref url="http://secunia.com/advisories/38794" source="SECUNIA" adv="1">38794</ref>
      <ref url="http://secunia.com/advisories/34759" source="SECUNIA" adv="1">34759</ref>
      <ref url="http://secunia.com/advisories/34710" source="SECUNIA" adv="1">34710</ref>
      <ref url="http://secunia.com/advisories/34694" source="SECUNIA" adv="1">34694</ref>
      <ref url="http://secunia.com/advisories/34642" source="SECUNIA" adv="1">34642</ref>
      <ref url="http://secunia.com/advisories/34418" source="SECUNIA" adv="1">34418</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9214" source="OVAL">oval:org.mitre.oval:def:9214</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2010/000082.html" source="MLIST">[security-announce] 20100303 VMSA-2010-0004 ESX Service Console and vMA third party updates</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.html" source="SUSE">SUSE-SR:2009:008</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html" source="SUSE">SUSE-SR:2009:007</ref>
      <ref url="http://launchpad.net/bugs/cve/2009-0115" source="MISC">http://launchpad.net/bugs/cve/2009-0115</ref>
      <ref url="http://download.opensuse.org/update/10.3-test/repodata/patch-kpartx-6082.xml" source="CONFIRM">http://download.opensuse.org/update/10.3-test/repodata/patch-kpartx-6082.xml</ref>
    </refs>
    <vuln_soft>
      <prod vendor="christophe.varoqui" name="multipath-tools">
        <vers num="0.4.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0119" published="2009-01-14" name="CVE-2009-0119" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .chm file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33204" source="BID">33204</ref>
      <ref url="http://www.milw0rm.com/exploits/7720" source="MILW0RM">7720</ref>
      <ref url="http://securityreason.com/securityalert/4912" source="SREASON">4912</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0120" published="2009-01-14" name="CVE-2009-0120" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The IBM WebSphere DataPower XML Security Gateway XS40 with firmware 3.6.1.5 allows remote attackers to cause a denial of service (device reboot) by sending data over an established SSL connection, as demonstrated by the abc\r\n\r\n string data.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0111" source="VUPEN">ADV-2009-0111</ref>
      <ref url="http://www.securitytracker.com/id?1021547" source="SECTRACK">1021547</ref>
      <ref url="http://www.securityfocus.com/bid/33169" source="BID">33169</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/499870/100/0/threaded" source="BUGTRAQ">20090108 [IBM Datapower XS40] Denial of Service</ref>
      <ref url="http://securityreason.com/securityalert/4911" source="SREASON">4911</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_datapower_xml_security_gateway_xs40">
        <vers num="3.6.1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0121" published="2009-01-14" name="CVE-2009-0121" modified="2009-01-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 allows remote attackers to execute arbitrary SQL commands via the password parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/33393" source="SECUNIA" adv="1">33393</ref>
    </refs>
    <vuln_soft>
      <prod vendor="goople_cms" name="goople_cms">
        <vers num="1.8.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0122" published="2009-01-15" name="CVE-2009-0122" modified="2009-01-31" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">hplip.postinst in HP Linux Imaging and Printing (HPLIP) 2.7.7 and 2.8.2 on Ubuntu allows local users to change the ownership of arbitrary files via unspecified manipulations in advance of an HPLIP installation or upgrade by an administrator, related to the product's attempt to correct the ownership of its configuration files within home directories.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33249" source="BID" patch="1">33249</ref>
      <ref url="https://launchpad.net/bugs/191299" source="CONFIRM">https://launchpad.net/bugs/191299</ref>
      <ref url="http://www.ubuntu.com/usn/usn-708-1" source="UBUNTU">USN-708-1</ref>
      <ref url="http://secunia.com/advisories/33539" source="SECUNIA">33539</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hplip">
        <vers num="2.7.7"/>
        <vers num="2.8.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0123" published="2009-01-15" name="CVE-2009-0123" modified="2009-01-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in Apple Safari on Mac OS X 10.5 and Windows allows remote attackers to read arbitrary files on a client machine via vectors related to the association of Safari with the (1) feed, (2) feeds, and (3) feedsearch URL types for RSS feeds.  NOTE: as of 20090114, the only disclosure is a vague pre-advisory. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47917" source="XF">safari-rss-feed-info-disclosure(47917)</ref>
      <ref url="http://www.securitytracker.com/id?1021581" source="SECTRACK">1021581</ref>
      <ref url="http://www.securityfocus.com/bid/33234" source="BID">33234</ref>
      <ref url="http://secunia.com/advisories/33458" source="SECUNIA">33458</ref>
      <ref url="http://isc.sans.org/diary.html?storyid=5689" source="MISC">http://isc.sans.org/diary.html?storyid=5689</ref>
      <ref url="http://brian.mastenbrook.net/display/27" source="MISC">http://brian.mastenbrook.net/display/27</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0124" published="2009-01-15" name="CVE-2009-0124" modified="2009-02-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The tqsl_verifyDataBlock function in openssl_cert.cpp in American Radio Relay League (ARRL) tqsllib 2.0 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00557.html" source="FEDORA">FEDORA-2009-0543</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=479650" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=479650</ref>
      <ref url="http://secunia.com/advisories/33543" source="SECUNIA">33543</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/01/12/4" source="MLIST">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511509" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511509</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arrl" name="tqsllib">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0125" published="2009-01-15" name="CVE-2009-0125" modified="2009-02-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">** DISPUTED **  NOTE: this issue has been disputed by the upstream vendor. nasl/nasl_crypto2.c in the Nessus Attack Scripting Language library (aka libnasl) 2.2.11 does not properly check the return value from the OpenSSL DSA_do_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.  NOTE: the upstream vendor has disputed this issue, stating "while we do misuse this function (this is a bug), it has absolutely no security ramification."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=479655" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=479655</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2009-January/002133.html" source="VIM">20090120 CVE-2009-0125 (fwd)</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/01/12/4" source="MLIST">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.html" source="SUSE">SUSE-SR:2009:003</ref>
      <ref url="http://cvs.fedoraproject.org/viewvc/rpms/libnasl/F-10/libnasl.spec?r1=1.16&amp;r2=1.17" source="CONFIRM">http://cvs.fedoraproject.org/viewvc/rpms/libnasl/F-10/libnasl.spec?r1=1.16&amp;r2=1.17</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511517" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511517</ref>
    </refs>
    <vuln_soft>
      <prod vendor="finkproject" name="libnasl">
        <vers num="2.2.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0126" published="2009-01-15" name="CVE-2009-0126" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infrastructure for Network Computing (BOINC) 6.2.14 and 6.4.5 does not check the return value from the OpenSSL RSA_public_decrypt function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00034.html" source="FEDORA">FEDORA-2009-0578</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=479664" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=479664</ref>
      <ref url="http://secunia.com/advisories/33828" source="SECUNIA">33828</ref>
      <ref url="http://secunia.com/advisories/33806" source="SECUNIA">33806</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/01/12/4" source="MLIST">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.html" source="SUSE">SUSE-SR:2009:003</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511521" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511521</ref>
      <ref url="http://boinc.berkeley.edu/trac/ticket/823" source="CONFIRM" adv="1">http://boinc.berkeley.edu/trac/ticket/823</ref>
      <ref url="http://boinc.berkeley.edu/trac/changeset/16883" source="CONFIRM">http://boinc.berkeley.edu/trac/changeset/16883</ref>
    </refs>
    <vuln_soft>
      <prod vendor="berkeley" name="boinc_client">
        <vers num="6.2.14"/>
        <vers num="6.4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0127" published="2009-01-15" name="CVE-2009-0127" modified="2009-01-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">** DISPUTED ** M2Crypto does not properly check the return value from the OpenSSL EVP_VerifyFinal, DSA_verify, ECDSA_verify, DSA_do_verify, and ECDSA_do_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.  NOTE: a Linux vendor disputes the relevance of this report to the M2Crypto product because "these functions are not used anywhere in m2crypto."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=479676" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=479676</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/01/12/4" source="MLIST">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511515" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511515</ref>
    </refs>
    <vuln_soft>
      <prod vendor="heikkitoivonen" name="m2crypto">
        <vers num="_nil_"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0128" published="2009-01-15" name="CVE-2009-0128" modified="2009-01-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">plugins/crypto/openssl/crypto_openssl.c in Simple Linux Utility for Resource Management (aka SLURM or slurm-llnl) does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://openwall.com/lists/oss-security/2009/01/12/4" source="MLIST">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511511" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511511</ref>
    </refs>
    <vuln_soft>
      <prod vendor="llnl" name="slurm">
        <vers num="_nil_"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0129" published="2009-01-15" name="CVE-2009-0129" modified="2009-01-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">libcrypt-openssl-dsa-perl does not properly check the return value from the OpenSSL DSA_verify and DSA_do_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://openwall.com/lists/oss-security/2009/01/12/4" source="MLIST">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511519" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511519</ref>
    </refs>
    <vuln_soft>
      <prod vendor="perl-openssl" name="libcrypt-openssl-dsa-perl">
        <vers num="_nil_"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0130" published="2009-01-15" name="CVE-2009-0130" modified="2009-01-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">** DISPUTED ** lib/crypto/c_src/crypto_drv.c in erlang does not properly check the return value from the OpenSSL DSA_do_verify function, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.  NOTE: a package maintainer disputes this issue, reporting that there is a proper check within the only code that uses the applicable part of crypto_drv.c, and thus "this report is invalid."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://openwall.com/lists/oss-security/2009/01/12/4" source="MLIST">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511520" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511520</ref>
    </refs>
    <vuln_soft>
      <prod vendor="erlang" name="erlang">
        <vers num="_nil_"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0131" published="2009-01-15" name="CVE-2009-0131" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The UFS implementation in the kernel in Sun OpenSolaris snv_29 through snv_90 allows local users to cause a denial of service (panic) via the single posix_fallocate test in the SUSv3 POSIX test suite, related to an F_ALLOCSP fcntl call.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1021600" source="SECTRACK">1021600</ref>
      <ref url="http://www.securityfocus.com/bid/33267" source="BID">33267</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-239188-1" source="SUNALERT">239188</ref>
      <ref url="http://bugs.opensolaris.org/view_bug.do?bug_id=6711995" source="CONFIRM">http://bugs.opensolaris.org/view_bug.do?bug_id=6711995</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_29" edition=""/>
        <vers num="snv_29" edition=":x86"/>
        <vers num="snv_29" edition=":sparc"/>
        <vers num="snv_30" edition=""/>
        <vers num="snv_30" edition=":sparc"/>
        <vers num="snv_30" edition=":x86"/>
        <vers num="snv_31" edition=""/>
        <vers num="snv_31" edition=":sparc"/>
        <vers num="snv_31" edition=":x86"/>
        <vers num="snv_32" edition=""/>
        <vers num="snv_32" edition=":x86"/>
        <vers num="snv_32" edition=":sparc"/>
        <vers num="snv_33" edition=""/>
        <vers num="snv_33" edition=":x86"/>
        <vers num="snv_33" edition=":sparc"/>
        <vers num="snv_34" edition=""/>
        <vers num="snv_34" edition=":sparc"/>
        <vers num="snv_34" edition=":x86"/>
        <vers num="snv_35" edition=""/>
        <vers num="snv_35" edition=":sparc"/>
        <vers num="snv_35" edition=":x86"/>
        <vers num="snv_36" edition=""/>
        <vers num="snv_36" edition=":sparc"/>
        <vers num="snv_36" edition=":x86"/>
        <vers num="snv_37" edition=""/>
        <vers num="snv_37" edition=":sparc"/>
        <vers num="snv_37" edition=":x86"/>
        <vers num="snv_38" edition=""/>
        <vers num="snv_38" edition=":sparc"/>
        <vers num="snv_38" edition=":x86"/>
        <vers num="snv_39" edition=""/>
        <vers num="snv_39" edition=":sparc"/>
        <vers num="snv_39" edition=":x86"/>
        <vers num="snv_40" edition=""/>
        <vers num="snv_40" edition=":x86"/>
        <vers num="snv_40" edition=":sparc"/>
        <vers num="snv_41" edition=""/>
        <vers num="snv_41" edition=":sparc"/>
        <vers num="snv_41" edition=":x86"/>
        <vers num="snv_42" edition=""/>
        <vers num="snv_42" edition=":x86"/>
        <vers num="snv_42" edition=":sparc"/>
        <vers num="snv_43" edition=""/>
        <vers num="snv_43" edition=":sparc"/>
        <vers num="snv_43" edition=":x86"/>
        <vers num="snv_44" edition=""/>
        <vers num="snv_44" edition=":x86"/>
        <vers num="snv_44" edition=":sparc"/>
        <vers num="snv_45" edition=""/>
        <vers num="snv_45" edition=":x86"/>
        <vers num="snv_45" edition=":sparc"/>
        <vers num="snv_46" edition=""/>
        <vers num="snv_46" edition=":sparc"/>
        <vers num="snv_46" edition=":x86"/>
        <vers num="snv_47" edition=""/>
        <vers num="snv_47" edition=":x86"/>
        <vers num="snv_47" edition=":sparc"/>
        <vers num="snv_48" edition=""/>
        <vers num="snv_48" edition=":sparc"/>
        <vers num="snv_48" edition=":x86"/>
        <vers num="snv_49" edition=""/>
        <vers num="snv_49" edition=":sparc"/>
        <vers num="snv_49" edition=":x86"/>
        <vers num="snv_50" edition=""/>
        <vers num="snv_50" edition=":sparc"/>
        <vers num="snv_50" edition=":x86"/>
        <vers num="snv_51" edition=""/>
        <vers num="snv_51" edition=":x86"/>
        <vers num="snv_51" edition=":sparc"/>
        <vers num="snv_52" edition=""/>
        <vers num="snv_52" edition=":x86"/>
        <vers num="snv_52" edition=":sparc"/>
        <vers num="snv_53" edition=""/>
        <vers num="snv_53" edition=":sparc"/>
        <vers num="snv_53" edition=":x86"/>
        <vers num="snv_54" edition=""/>
        <vers num="snv_54" edition=":sparc"/>
        <vers num="snv_54" edition=":x86"/>
        <vers num="snv_55" edition=""/>
        <vers num="snv_55" edition=":sparc"/>
        <vers num="snv_55" edition=":x86"/>
        <vers num="snv_56" edition=""/>
        <vers num="snv_56" edition=":x86"/>
        <vers num="snv_56" edition=":sparc"/>
        <vers num="snv_57" edition=""/>
        <vers num="snv_57" edition=":x86"/>
        <vers num="snv_57" edition=":sparc"/>
        <vers num="snv_58" edition=""/>
        <vers num="snv_58" edition=":sparc"/>
        <vers num="snv_58" edition=":x86"/>
        <vers num="snv_59" edition=""/>
        <vers num="snv_59" edition=":sparc"/>
        <vers num="snv_59" edition=":x86"/>
        <vers num="snv_60" edition=""/>
        <vers num="snv_60" edition=":x86"/>
        <vers num="snv_60" edition=":sparc"/>
        <vers num="snv_61" edition=""/>
        <vers num="snv_61" edition=":sparc"/>
        <vers num="snv_61" edition=":x86"/>
        <vers num="snv_62" edition=""/>
        <vers num="snv_62" edition=":x86"/>
        <vers num="snv_62" edition=":sparc"/>
        <vers num="snv_63" edition=""/>
        <vers num="snv_63" edition=":x86"/>
        <vers num="snv_63" edition=":sparc"/>
        <vers num="snv_64" edition=""/>
        <vers num="snv_64" edition=":x86"/>
        <vers num="snv_64" edition=":sparc"/>
        <vers num="snv_65" edition=""/>
        <vers num="snv_65" edition=":sparc"/>
        <vers num="snv_65" edition=":x86"/>
        <vers num="snv_66" edition=""/>
        <vers num="snv_66" edition=":x86"/>
        <vers num="snv_66" edition=":sparc"/>
        <vers num="snv_67" edition=""/>
        <vers num="snv_67" edition=":sparc"/>
        <vers num="snv_67" edition=":x86"/>
        <vers num="snv_68" edition=""/>
        <vers num="snv_68" edition=":x86"/>
        <vers num="snv_68" edition=":sparc"/>
        <vers num="snv_69" edition=""/>
        <vers num="snv_69" edition=":sparc"/>
        <vers num="snv_69" edition=":x86"/>
        <vers num="snv_70" edition=""/>
        <vers num="snv_70" edition=":sparc"/>
        <vers num="snv_70" edition=":x86"/>
        <vers num="snv_71" edition=""/>
        <vers num="snv_71" edition=":sparc"/>
        <vers num="snv_71" edition=":x86"/>
        <vers num="snv_72" edition=""/>
        <vers num="snv_72" edition=":x86"/>
        <vers num="snv_72" edition=":sparc"/>
        <vers num="snv_73" edition=""/>
        <vers num="snv_73" edition=":x86"/>
        <vers num="snv_73" edition=":sparc"/>
        <vers num="snv_74" edition=""/>
        <vers num="snv_74" edition=":x86"/>
        <vers num="snv_74" edition=":sparc"/>
        <vers num="snv_75" edition=""/>
        <vers num="snv_75" edition=":x86"/>
        <vers num="snv_75" edition=":sparc"/>
        <vers num="snv_76" edition=""/>
        <vers num="snv_76" edition=":sparc"/>
        <vers num="snv_76" edition=":x86"/>
        <vers num="snv_77" edition=""/>
        <vers num="snv_77" edition=":sparc"/>
        <vers num="snv_77" edition=":x86"/>
        <vers num="snv_78" edition=""/>
        <vers num="snv_78" edition=":sparc"/>
        <vers num="snv_78" edition=":x86"/>
        <vers num="snv_79" edition=""/>
        <vers num="snv_79" edition=":x86"/>
        <vers num="snv_79" edition=":sparc"/>
        <vers num="snv_80" edition=""/>
        <vers num="snv_80" edition=":x86"/>
        <vers num="snv_80" edition=":sparc"/>
        <vers num="snv_81" edition=""/>
        <vers num="snv_81" edition=":x86"/>
        <vers num="snv_81" edition=":sparc"/>
        <vers num="snv_82" edition=""/>
        <vers num="snv_82" edition=":x86"/>
        <vers num="snv_82" edition=":sparc"/>
        <vers num="snv_83" edition=""/>
        <vers num="snv_83" edition=":sparc"/>
        <vers num="snv_83" edition=":x86"/>
        <vers num="snv_84" edition=""/>
        <vers num="snv_84" edition=":x86"/>
        <vers num="snv_84" edition=":sparc"/>
        <vers num="snv_85" edition=""/>
        <vers num="snv_85" edition=":sparc"/>
        <vers num="snv_85" edition=":x86"/>
        <vers num="snv_86" edition=""/>
        <vers num="snv_86" edition=":sparc"/>
        <vers num="snv_86" edition=":x86"/>
        <vers num="snv_87" edition=""/>
        <vers num="snv_87" edition=":sparc"/>
        <vers num="snv_87" edition=":x86"/>
        <vers num="snv_88" edition=""/>
        <vers num="snv_88" edition=":x86"/>
        <vers num="snv_88" edition=":sparc"/>
        <vers num="snv_89" edition=""/>
        <vers num="snv_89" edition=":x86"/>
        <vers num="snv_89" edition=":sparc"/>
        <vers num="snv_90" edition=""/>
        <vers num="snv_90" edition=":sparc"/>
        <vers num="snv_90" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0132" published="2009-01-15" name="CVE-2009-0132" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Integer overflow in the aio_suspend function in Sun Solaris 8 through 10 and OpenSolaris, when 32-bit mode is enabled, allows local users to cause a denial of service (panic) via a large integer value in the second argument (aka nent argument).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33188" source="BID" patch="1">33188</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-117350-59-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-117350-59-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0099" source="VUPEN">ADV-2009-0099</ref>
      <ref url="http://www.trapkit.de/advisories/TKADV2009-001.txt" source="MISC">http://www.trapkit.de/advisories/TKADV2009-001.txt</ref>
      <ref url="http://www.securitytracker.com/id?1021553" source="SECTRACK">1021553</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-247986-1" source="SUNALERT" adv="1">247986</ref>
      <ref url="http://secunia.com/advisories/33516" source="SECUNIA">33516</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="" edition=":sparc"/>
        <vers num="" edition=":x86"/>
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10" edition=""/>
        <vers num="10" edition=":x86"/>
        <vers num="10" edition=":sparc"/>
        <vers num="8" edition=""/>
        <vers num="8" edition=":x86"/>
        <vers num="8" edition=":sparc"/>
        <vers num="9" edition=""/>
        <vers num="9" edition=":sparc"/>
        <vers num="9" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0133" published="2009-01-15" name="CVE-2009-0133" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary code via a .hhp file with a long "Index file" field, possibly a related issue to CVE-2006-0564.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/7727" source="MILW0RM">7727</ref>
      <ref url="http://securityreason.com/securityalert/4914" source="SREASON">4914</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="html_help_workshop">
        <vers num="4.74"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0134" published="2009-01-16" name="CVE-2009-0134" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Insecure method vulnerability in the EasyGrid.SGCtrl.32 ActiveX control in EasyGrid.ocx 1.0.0.1 in AAA EasyGrid ActiveX 3.51 allows remote attackers to create and overwrite arbitrary files via the (1) DoSaveFile or (2) DoSaveHtmlFile method.  NOTE: vector 1 could be leveraged for code execution by creating executable files in Startup folders or by accessing files using hcp:// URLs.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47946" source="XF">easygrid-activex-dosavefile-file-overwrite(47946)</ref>
      <ref url="http://www.securityfocus.com/bid/33272" source="BID">33272</ref>
      <ref url="http://www.milw0rm.com/exploits/7779" source="MILW0RM">7779</ref>
      <ref url="http://securityreason.com/securityalert/4913" source="SREASON">4913</ref>
      <ref url="http://secunia.com/advisories/33537" source="SECUNIA" adv="1">33537</ref>
    </refs>
    <vuln_soft>
      <prod vendor="share2" name="easy_grid_control">
        <vers num="3.51"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0135" published="2009-01-16" name="CVE-2009-0135" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple integer overflows in the Audible::Tag::readTag function in metadata/audible/audibletag.cpp in Amarok 1.4.10 through 2.0.1 allow remote attackers to execute arbitrary code via an Audible Audio (.aa) file with a large (1) nlen or (2) vlen Tag value, each of which triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00708.html" source="FEDORA">FEDORA-2009-0715</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=479946" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=479946</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=479560" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=479560</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0100" source="VUPEN">ADV-2009-0100</ref>
      <ref url="http://www.ubuntu.com/usn/USN-739-1" source="UBUNTU">USN-739-1</ref>
      <ref url="http://www.securitytracker.com/id?1021558" source="SECTRACK">1021558</ref>
      <ref url="http://www.securityfocus.com/bid/33210" source="BID">33210</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/499984/100/0/threaded" source="BUGTRAQ">20090111 [TKADV2009-002] Amarok Integer Overflow and Unchecked Allocation Vulnerabilities</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:030" source="MANDRIVA">MDVSA-2009:030</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1706" source="DEBIAN">DSA-1706</ref>
      <ref url="http://websvn.kde.org/?view=rev&amp;revision=908415" source="CONFIRM">http://websvn.kde.org/?view=rev&amp;revision=908415</ref>
      <ref url="http://websvn.kde.org/?view=rev&amp;revision=908401" source="CONFIRM">http://websvn.kde.org/?view=rev&amp;revision=908401</ref>
      <ref url="http://websvn.kde.org/?view=rev&amp;revision=908391" source="CONFIRM">http://websvn.kde.org/?view=rev&amp;revision=908391</ref>
      <ref url="http://trapkit.de/advisories/TKADV2009-002.txt" source="MISC">http://trapkit.de/advisories/TKADV2009-002.txt</ref>
      <ref url="http://securityreason.com/securityalert/4915" source="SREASON">4915</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200903-34.xml" source="GENTOO">GLSA-200903-34</ref>
      <ref url="http://secunia.com/advisories/34407" source="SECUNIA">34407</ref>
      <ref url="http://secunia.com/advisories/34315" source="SECUNIA">34315</ref>
      <ref url="http://secunia.com/advisories/33819" source="SECUNIA">33819</ref>
      <ref url="http://secunia.com/advisories/33640" source="SECUNIA">33640</ref>
      <ref url="http://secunia.com/advisories/33522" source="SECUNIA">33522</ref>
      <ref url="http://secunia.com/advisories/33505" source="SECUNIA" adv="1">33505</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/01/14/2" source="MLIST">[oss-security] 20090114 CVE Request -- amarok</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.html" source="SUSE">SUSE-SR:2009:003</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=254896" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=254896</ref>
      <ref url="http://amarok.kde.org/en/releases/2.0.1.1" source="CONFIRM" adv="1">http://amarok.kde.org/en/releases/2.0.1.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="amarok" name="amarok">
        <vers num="1.4.10"/>
        <vers num="2.0"/>
        <vers num="2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0136" published="2009-01-16" name="CVE-2009-0136" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple array index errors in the Audible::Tag::readTag function in metadata/audible/audibletag.cpp in Amarok 1.4.10 through 2.0.1 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via an Audible Audio (.aa) file with a crafted (1) nlen or (2) vlen Tag value, each of which can lead to an invalid pointer dereference, or the writing of a 0x00 byte to an arbitrary memory location, after an allocation failure.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00708.html" source="FEDORA">FEDORA-2009-0715</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=479946" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=479946</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=479560" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=479560</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0100" source="VUPEN">ADV-2009-0100</ref>
      <ref url="http://www.ubuntu.com/usn/USN-739-1" source="UBUNTU">USN-739-1</ref>
      <ref url="http://www.securitytracker.com/id?1021558" source="SECTRACK">1021558</ref>
      <ref url="http://www.securityfocus.com/bid/33210" source="BID">33210</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/499984/100/0/threaded" source="BUGTRAQ">20090111 [TKADV2009-002] Amarok Integer Overflow and Unchecked Allocation Vulnerabilities</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:030" source="MANDRIVA">MDVSA-2009:030</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1706" source="DEBIAN">DSA-1706</ref>
      <ref url="http://websvn.kde.org/?view=rev&amp;revision=908415" source="CONFIRM">http://websvn.kde.org/?view=rev&amp;revision=908415</ref>
      <ref url="http://websvn.kde.org/?view=rev&amp;revision=908401" source="CONFIRM">http://websvn.kde.org/?view=rev&amp;revision=908401</ref>
      <ref url="http://websvn.kde.org/?view=rev&amp;revision=908391" source="CONFIRM">http://websvn.kde.org/?view=rev&amp;revision=908391</ref>
      <ref url="http://trapkit.de/advisories/TKADV2009-002.txt" source="MISC">http://trapkit.de/advisories/TKADV2009-002.txt</ref>
      <ref url="http://securityreason.com/securityalert/4915" source="SREASON">4915</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200903-34.xml" source="GENTOO">GLSA-200903-34</ref>
      <ref url="http://secunia.com/advisories/34407" source="SECUNIA">34407</ref>
      <ref url="http://secunia.com/advisories/34315" source="SECUNIA">34315</ref>
      <ref url="http://secunia.com/advisories/33819" source="SECUNIA">33819</ref>
      <ref url="http://secunia.com/advisories/33640" source="SECUNIA">33640</ref>
      <ref url="http://secunia.com/advisories/33522" source="SECUNIA">33522</ref>
      <ref url="http://secunia.com/advisories/33505" source="SECUNIA" adv="1">33505</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/01/14/2" source="MLIST">[oss-security] 20090114 CVE Request -- amarok</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.html" source="SUSE">SUSE-SR:2009:003</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=254896" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=254896</ref>
      <ref url="http://amarok.kde.org/en/releases/2.0.1.1" source="CONFIRM" adv="1">http://amarok.kde.org/en/releases/2.0.1.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="amarok" name="amarok">
        <vers num="1.4.10"/>
        <vers num="2.0"/>
        <vers num="2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0137" published="2009-02-12" name="CVE-2009-0137" modified="2009-08-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Safari RSS in Apple Mac OS X 10.4.11 and 10.5.6, and Windows XP and Vista, allow remote attackers to execute arbitrary JavaScript in the local security zone via a crafted feed: URL, related to "input validation issues."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-02-12</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-02-12</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0138" published="2009-02-12" name="CVE-2009-0138" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">servermgrd (Server Manager) in Apple Mac OS X 10.5.6 does not properly validate authentication credentials, which allows remote attackers to modify the system configuration.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-02-12</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://www.securityfocus.com/bid/33813" source="BID">33813</ref>
      <ref url="http://www.securityfocus.com/bid/33759" source="BID">33759</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA">33937</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0139" published="2009-02-12" name="CVE-2009-0139" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in the SMB component in Apple Mac OS X 10.5.6 allows remote SMB servers to cause a denial of service (system shutdown) or execute arbitrary code via a crafted SMB file system that triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-02-12</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA">33937</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0140" published="2009-02-12" name="CVE-2009-0140" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the SMB component in Apple Mac OS X 10.4.11 and 10.5.6 allows remote SMB servers to cause a denial of service (memory exhaustion and system shutdown) via a crafted file system name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-02-12</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA">33937</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0141" published="2009-02-12" name="CVE-2009-0141" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">XTerm in Apple Mac OS X 10.4.11 and 10.5.6, when used with luit, creates tty devices with insecure world-writable permissions, which allows local users to write to the Xterm of another user.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48727" source="XF">macosx-xterm-information-disclosure(48727)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://www.securityfocus.com/bid/33759" source="BID">33798</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://securitytracker.com/alerts/2009/Feb/1021729.html" source="SECTRACK">1021729</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA">33937</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE" adv="1">APPLE-SA-2009-02-12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0142" published="2009-02-12" name="CVE-2009-0142" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">Race condition in AFP Server in Apple Mac OS X 10.5.6 allows local users to cause a denial of service (infinite loop) via unspecified vectors related to "file enumeration logic."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://www.securityfocus.com/bid/33812" source="BID">33812</ref>
      <ref url="http://www.securityfocus.com/bid/33759" source="BID">33759</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA">33937</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE">APPLE-SA-2009-02-12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0143" published="2009-03-14" name="CVE-2009-0143" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Apple iTunes before 8.1 does not properly inform the user about the origin of an authentication request, which makes it easier for remote podcast servers to trick a user into providing a username and password when subscribing to a crafted podcast.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT3487" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3487</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2009/Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-03-11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49201" source="XF">itunes-podcast-information-disclosure(49201)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0702" source="VUPEN">ADV-2009-0702</ref>
      <ref url="http://www.securityfocus.com/bid/34094" source="BID">34094</ref>
      <ref url="http://securitytracker.com/id?1021843" source="SECTRACK">1021843</ref>
      <ref url="http://secunia.com/advisories/34254" source="SECUNIA" adv="1">34254</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5336" source="OVAL">oval:org.mitre.oval:def:5336</ref>
      <ref url="http://osvdb.org/52579" source="OSVDB">52579</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="1.0" edition="-"/>
        <vers num="1.0" edition="-:windows"/>
        <vers num="1.0" edition="-:mac"/>
        <vers num="1.1.1" edition="-"/>
        <vers num="1.1.1" edition="-:windows"/>
        <vers num="1.1.1" edition="-:mac"/>
        <vers num="1.1.2" edition="-"/>
        <vers num="1.1.2" edition="-:windows"/>
        <vers num="1.1.2" edition="-:mac"/>
        <vers num="2.0" edition="-"/>
        <vers num="2.0" edition="-:windows"/>
        <vers num="2.0" edition="-:mac"/>
        <vers num="2.0.1" edition="-"/>
        <vers num="2.0.1" edition="-:windows"/>
        <vers num="2.0.1" edition="-:mac"/>
        <vers num="2.0.2" edition="-"/>
        <vers num="2.0.2" edition="-:mac"/>
        <vers num="2.0.2" edition="-:windows"/>
        <vers num="2.0.3" edition="-"/>
        <vers num="2.0.3" edition="-:windows"/>
        <vers num="2.0.3" edition="-:mac"/>
        <vers num="2.0.4" edition="-"/>
        <vers num="2.0.4" edition="-:windows"/>
        <vers num="2.0.4" edition="-:mac"/>
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":windows"/>
        <vers num="3.0.1" edition=""/>
        <vers num="3.0.1" edition=":windows"/>
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":windows"/>
        <vers num="4.0.0" edition="-"/>
        <vers num="4.0.0" edition="-:mac"/>
        <vers num="4.0.0" edition="-:windows"/>
        <vers num="4.0.1" edition=""/>
        <vers num="4.0.1" edition=":windows"/>
        <vers num="4.0.1" edition="-"/>
        <vers num="4.0.1" edition="-:windows"/>
        <vers num="4.0.1" edition="-:mac"/>
        <vers num="4.1" edition=""/>
        <vers num="4.1" edition=":windows"/>
        <vers num="4.1.0" edition="-"/>
        <vers num="4.1.0" edition="-:windows"/>
        <vers num="4.1.0" edition="-:mac"/>
        <vers num="4.2" edition=""/>
        <vers num="4.2" edition=":windows"/>
        <vers num="4.2.0" edition="-"/>
        <vers num="4.2.0" edition="-:windows"/>
        <vers num="4.2.0" edition="-:mac"/>
        <vers num="4.2.72" edition=""/>
        <vers num="4.2.72" edition=":windows"/>
        <vers num="4.5" edition=""/>
        <vers num="4.5" edition=":windows"/>
        <vers num="4.5.0" edition="-"/>
        <vers num="4.5.0" edition="-:windows"/>
        <vers num="4.5.0" edition="-:mac"/>
        <vers num="4.6" edition=""/>
        <vers num="4.6" edition=":windows"/>
        <vers num="4.6.0" edition="-"/>
        <vers num="4.6.0" edition="-:mac"/>
        <vers num="4.6.0" edition="-:windows"/>
        <vers num="4.7" edition=""/>
        <vers num="4.7" edition=":windows"/>
        <vers num="4.7.0" edition="-"/>
        <vers num="4.7.0" edition="-:mac"/>
        <vers num="4.7.0" edition="-:windows"/>
        <vers num="4.7.1" edition=""/>
        <vers num="4.7.1" edition=":windows"/>
        <vers num="4.7.1" edition="-"/>
        <vers num="4.7.1" edition="-:mac"/>
        <vers num="4.7.1" edition="-:windows"/>
        <vers num="4.7.1.30" edition=""/>
        <vers num="4.7.1.30" edition=":windows"/>
        <vers num="4.8" edition=""/>
        <vers num="4.8" edition=":windows"/>
        <vers num="4.8.0" edition="-"/>
        <vers num="4.8.0" edition="-:mac"/>
        <vers num="4.8.0" edition="-:windows"/>
        <vers num="4.9" edition=""/>
        <vers num="4.9" edition=":windows"/>
        <vers num="4.9.0" edition="-"/>
        <vers num="4.9.0" edition="-:windows"/>
        <vers num="4.9.0" edition="-:mac"/>
        <vers num="5.0" edition=""/>
        <vers num="5.0" edition=":windows"/>
        <vers num="5.0.0" edition="-"/>
        <vers num="5.0.0" edition="-:mac"/>
        <vers num="5.0.0" edition="-:windows"/>
        <vers num="5.0.1" edition=""/>
        <vers num="5.0.1" edition=":windows"/>
        <vers num="5.0.1" edition="-"/>
        <vers num="5.0.1" edition="-:mac"/>
        <vers num="5.0.1" edition="-:windows"/>
        <vers num="6.0" edition=""/>
        <vers num="6.0" edition=":windows"/>
        <vers num="6.0.0" edition="-"/>
        <vers num="6.0.0" edition="-:windows"/>
        <vers num="6.0.0" edition="-:mac"/>
        <vers num="6.0.1" edition=""/>
        <vers num="6.0.1" edition=":windows"/>
        <vers num="6.0.1" edition="-"/>
        <vers num="6.0.1" edition="-:mac"/>
        <vers num="6.0.1" edition="-:windows"/>
        <vers num="6.0.2" edition=""/>
        <vers num="6.0.2" edition=":windows"/>
        <vers num="6.0.2" edition="-"/>
        <vers num="6.0.2" edition="-:mac"/>
        <vers num="6.0.2" edition="-:windows"/>
        <vers num="6.0.3" edition=""/>
        <vers num="6.0.3" edition=":windows"/>
        <vers num="6.0.3" edition="-"/>
        <vers num="6.0.3" edition="-:mac"/>
        <vers num="6.0.3" edition="-:windows"/>
        <vers num="6.0.4" edition=""/>
        <vers num="6.0.4" edition=":windows"/>
        <vers num="6.0.4" edition="-"/>
        <vers num="6.0.4" edition="-:windows"/>
        <vers num="6.0.4" edition="-:mac"/>
        <vers num="6.0.4.2" edition=""/>
        <vers num="6.0.4.2" edition=":windows"/>
        <vers num="6.0.5" edition=""/>
        <vers num="6.0.5" edition=":windows"/>
        <vers num="6.0.5" edition="-"/>
        <vers num="6.0.5" edition="-:mac"/>
        <vers num="6.0.5" edition="-:windows"/>
        <vers num="7.0.0" edition="-"/>
        <vers num="7.0.0" edition="-:mac"/>
        <vers num="7.0.0" edition="-:windows"/>
        <vers num="7.0.1" edition="-"/>
        <vers num="7.0.1" edition="-:windows"/>
        <vers num="7.0.1" edition="-:mac"/>
        <vers num="7.0.2" edition=""/>
        <vers num="7.0.2" edition=":windows"/>
        <vers num="7.0.2" edition="-"/>
        <vers num="7.0.2" edition="-:windows"/>
        <vers num="7.0.2" edition="-:mac"/>
        <vers num="7.1.0" edition="-"/>
        <vers num="7.1.0" edition="-:windows"/>
        <vers num="7.1.0" edition="-:mac"/>
        <vers num="7.1.1" edition="-"/>
        <vers num="7.1.1" edition="-:windows"/>
        <vers num="7.1.1" edition="-:mac"/>
        <vers num="7.2.0" edition="-"/>
        <vers num="7.2.0" edition="-:windows"/>
        <vers num="7.2.0" edition="-:mac"/>
        <vers num="7.3.0" edition="-"/>
        <vers num="7.3.0" edition="-:windows"/>
        <vers num="7.3.0" edition="-:mac"/>
        <vers num="7.3.1" edition="-"/>
        <vers num="7.3.1" edition="-:windows"/>
        <vers num="7.3.1" edition="-:mac"/>
        <vers num="7.3.2" edition=""/>
        <vers num="7.3.2" edition=":windows"/>
        <vers num="7.3.2" edition="-"/>
        <vers num="7.3.2" edition="-:mac"/>
        <vers num="7.3.2" edition="-:windows"/>
        <vers num="7.4" edition=""/>
        <vers num="7.4" edition=":windows"/>
        <vers num="7.4.0" edition="-"/>
        <vers num="7.4.0" edition="-:windows"/>
        <vers num="7.4.0" edition="-:mac"/>
        <vers num="7.4.1" edition=""/>
        <vers num="7.4.1" edition=":windows"/>
        <vers num="7.4.1" edition="-"/>
        <vers num="7.4.1" edition="-:mac"/>
        <vers num="7.4.1" edition="-:windows"/>
        <vers num="7.4.2" edition=""/>
        <vers num="7.4.2" edition=":windows"/>
        <vers num="7.4.2" edition="-"/>
        <vers num="7.4.2" edition="-:windows"/>
        <vers num="7.4.2" edition="-:mac"/>
        <vers num="7.4.3" edition=""/>
        <vers num="7.4.3" edition=":windows"/>
        <vers num="7.5" edition=""/>
        <vers num="7.5" edition=":windows"/>
        <vers num="7.5.0" edition="-"/>
        <vers num="7.5.0" edition="-:windows"/>
        <vers num="7.5.0" edition="-:mac"/>
        <vers num="7.6" edition=""/>
        <vers num="7.6" edition=":windows"/>
        <vers num="7.6.0" edition="-"/>
        <vers num="7.6.0" edition="-:windows"/>
        <vers num="7.6.0" edition="-:mac"/>
        <vers num="7.6.1" edition=""/>
        <vers num="7.6.1" edition=":windows"/>
        <vers num="7.6.1" edition="-"/>
        <vers num="7.6.1" edition="-:windows"/>
        <vers num="7.6.1" edition="-:mac"/>
        <vers num="7.6.2" edition=""/>
        <vers num="7.6.2" edition=":windows"/>
        <vers num="7.6.2" edition="-"/>
        <vers num="7.6.2" edition="-:mac"/>
        <vers num="7.6.2" edition="-:windows"/>
        <vers num="7.7" edition=""/>
        <vers num="7.7" edition=":windows"/>
        <vers num="7.7.0" edition="-"/>
        <vers num="7.7.0" edition="-:mac"/>
        <vers num="7.7.0" edition="-:windows"/>
        <vers num="7.7.1" edition=""/>
        <vers num="7.7.1" edition=":windows"/>
        <vers num="7.7.1" edition="-"/>
        <vers num="7.7.1" edition="-:mac"/>
        <vers num="7.7.1" edition="-:windows"/>
        <vers prev="1" num="8.0" edition=""/>
        <vers prev="1" num="8.0" edition=":windows"/>
        <vers prev="1" num="8.0" edition="-"/>
        <vers prev="1" num="8.0" edition="-:mac"/>
        <vers num="8.0.0" edition="-"/>
        <vers num="8.0.0" edition="-:mac"/>
        <vers num="8.0.0" edition="-:windows"/>
        <vers prev="1" num="8.0.1" edition="-"/>
        <vers prev="1" num="8.0.1" edition="-:mac"/>
        <vers prev="1" num="8.0.1" edition="-:windows"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0144" published="2009-05-13" name="CVE-2009-0144" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">CFNetwork in Apple Mac OS X 10.5 before 10.5.7 does not properly parse noncompliant Set-Cookie headers, which allows remote attackers to obtain sensitive information by sniffing the network for "secure cookies" that are sent over unencrypted HTTP connections.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50479" source="XF">macos-cfnetwork-info-disclosure(50479)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securitytracker.com/id?1022214" source="SECTRACK">1022214</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0145" published="2009-05-13" name="CVE-2009-0145" modified="2009-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">CoreGraphics in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF file that triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50481" source="XF">macos-coregraphics-pdf-code-execution(50481)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN">ADV-2009-1522</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securitytracker.com/id?1022209" source="SECTRACK">1022209</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA">35379</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE">APPLE-SA-2009-06-08-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0146" published="2009-04-23" name="CVE-2009-0146" modified="2010-12-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2SymbolDict::setBitmap and (2) JBIG2Stream::readSymbolDictSeg.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0430.html" source="REDHAT" patch="1">RHSA-2009:0430</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01291.html" source="FEDORA">FEDORA-2009-6982</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01277.html" source="FEDORA">FEDORA-2009-6973</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00567.html" source="FEDORA">FEDORA-2009-6972</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=490612" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=490612</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1040" source="VUPEN" adv="1">ADV-2010-1040</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN" adv="1">ADV-2009-1621</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN" adv="1">ADV-2009-1297</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1077" source="VUPEN" adv="1">ADV-2009-1077</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1066" source="VUPEN" adv="1">ADV-2009-1066</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1065" source="VUPEN" adv="1">ADV-2009-1065</ref>
      <ref url="http://www.securitytracker.com/id?1022073" source="SECTRACK">1022073</ref>
      <ref url="http://www.securityfocus.com/bid/34568" source="BID">34568</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502761/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0059-1 poppler</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502750/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0061-1 cups</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0480.html" source="REDHAT">RHSA-2009:0480</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0431.html" source="REDHAT">RHSA-2009:0431</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0429.html" source="REDHAT">RHSA-2009:0429</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:087" source="MANDRIVA">MDVSA-2010:087</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:101" source="MANDRIVA">MDVSA-2009:101</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1793" source="DEBIAN">DSA-1793</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1790" source="DEBIAN">DSA-1790</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0061" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0061</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0059" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0059</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.578477" source="SLACKWARE">SSA:2009-129-01</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-20.xml" source="GENTOO">GLSA-200904-20</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA" adv="1">35685</ref>
      <ref url="http://secunia.com/advisories/35618" source="SECUNIA" adv="1">35618</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA" adv="1">35074</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA" adv="1">35065</ref>
      <ref url="http://secunia.com/advisories/35064" source="SECUNIA" adv="1">35064</ref>
      <ref url="http://secunia.com/advisories/35037" source="SECUNIA">35037</ref>
      <ref url="http://secunia.com/advisories/34991" source="SECUNIA" adv="1">34991</ref>
      <ref url="http://secunia.com/advisories/34963" source="SECUNIA">34963</ref>
      <ref url="http://secunia.com/advisories/34959" source="SECUNIA" adv="1">34959</ref>
      <ref url="http://secunia.com/advisories/34852" source="SECUNIA" adv="1">34852</ref>
      <ref url="http://secunia.com/advisories/34756" source="SECUNIA">34756</ref>
      <ref url="http://secunia.com/advisories/34755" source="SECUNIA" adv="1">34755</ref>
      <ref url="http://secunia.com/advisories/34481" source="SECUNIA" adv="1">34481</ref>
      <ref url="http://secunia.com/advisories/34291" source="SECUNIA" adv="1">34291</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0458.html" source="REDHAT">RHSA-2009:0458</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9632" source="OVAL">oval:org.mitre.oval:def:9632</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.html" source="SUSE">SUSE-SA:2009:024</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=263028" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=263028</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.10-1"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19" edition="rc1"/>
        <vers num="1.1.19" edition="rc2"/>
        <vers num="1.1.19" edition="rc3"/>
        <vers num="1.1.19" edition="rc4"/>
        <vers num="1.1.19" edition="rc5"/>
        <vers num="1.1.2"/>
        <vers num="1.1.20" edition="rc1"/>
        <vers num="1.1.20" edition="rc2"/>
        <vers num="1.1.20" edition="rc3"/>
        <vers num="1.1.20" edition="rc4"/>
        <vers num="1.1.20" edition="rc5"/>
        <vers num="1.1.20" edition="rc6"/>
        <vers num="1.1.21" edition="rc1"/>
        <vers num="1.1.21" edition="rc2"/>
        <vers num="1.1.22" edition="rc1"/>
        <vers num="1.1.22" edition="rc2"/>
        <vers num="1.1.23" edition="rc1"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.5-1"/>
        <vers num="1.1.5-2"/>
        <vers num="1.1.6"/>
        <vers num="1.1.6-1"/>
        <vers num="1.1.6-2"/>
        <vers num="1.1.6-3"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.1.9-1"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.10"/>
        <vers num="1.2.11"/>
        <vers num="1.2.12"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.2.8"/>
        <vers num="1.2.9"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.10"/>
        <vers num="1.3.11"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.5"/>
        <vers num="1.3.6"/>
        <vers num="1.3.7"/>
        <vers num="1.3.8"/>
        <vers prev="1" num="1.3.9"/>
      </prod>
      <prod vendor="foolabs" name="xpdf">
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.5a"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7a"/>
        <vers num="0.80"/>
        <vers num="0.90"/>
        <vers num="0.91"/>
        <vers num="0.91a"/>
        <vers num="0.91b"/>
        <vers num="0.91c"/>
        <vers num="0.92"/>
        <vers num="0.92a"/>
        <vers num="0.92b"/>
        <vers num="0.92c"/>
        <vers num="0.92d"/>
        <vers num="0.92e"/>
        <vers num="0.93"/>
        <vers num="0.93a"/>
        <vers num="0.93b"/>
        <vers num="0.93c"/>
        <vers num="1.00"/>
        <vers num="1.00a"/>
        <vers num="1.01"/>
        <vers num="2.00"/>
        <vers num="2.01"/>
        <vers num="2.02"/>
        <vers num="2.03"/>
        <vers num="3.00"/>
        <vers num="3.01"/>
        <vers prev="1" num="3.02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0147" published="2009-04-23" name="CVE-2009-0147" modified="2010-12-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg, and (3) JBIG2Stream::readGenericBitmap.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0430.html" source="REDHAT" patch="1">RHSA-2009:0430</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01291.html" source="FEDORA">FEDORA-2009-6982</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01277.html" source="FEDORA">FEDORA-2009-6973</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00567.html" source="FEDORA">FEDORA-2009-6972</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=490614" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=490614</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1040" source="VUPEN" adv="1">ADV-2010-1040</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN" adv="1">ADV-2009-1621</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN" adv="1">ADV-2009-1297</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1077" source="VUPEN" adv="1">ADV-2009-1077</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1066" source="VUPEN" adv="1">ADV-2009-1066</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1065" source="VUPEN" adv="1">ADV-2009-1065</ref>
      <ref url="http://www.securitytracker.com/id?1022073" source="SECTRACK">1022073</ref>
      <ref url="http://www.securityfocus.com/bid/34568" source="BID">34568</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502761/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0059-1 poppler</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502750/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0061-1 cups</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0480.html" source="REDHAT">RHSA-2009:0480</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0431.html" source="REDHAT">RHSA-2009:0431</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0429.html" source="REDHAT">RHSA-2009:0429</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:087" source="MANDRIVA">MDVSA-2010:087</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:101" source="MANDRIVA">MDVSA-2009:101</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1793" source="DEBIAN">DSA-1793</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1790" source="DEBIAN">DSA-1790</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0061" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0061</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0059" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0059</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.578477" source="SLACKWARE">SSA:2009-129-01</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-20.xml" source="GENTOO">GLSA-200904-20</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA" adv="1">35685</ref>
      <ref url="http://secunia.com/advisories/35618" source="SECUNIA" adv="1">35618</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA" adv="1">35074</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA" adv="1">35065</ref>
      <ref url="http://secunia.com/advisories/35064" source="SECUNIA" adv="1">35064</ref>
      <ref url="http://secunia.com/advisories/35037" source="SECUNIA" adv="1">35037</ref>
      <ref url="http://secunia.com/advisories/34991" source="SECUNIA" adv="1">34991</ref>
      <ref url="http://secunia.com/advisories/34963" source="SECUNIA" adv="1">34963</ref>
      <ref url="http://secunia.com/advisories/34959" source="SECUNIA" adv="1">34959</ref>
      <ref url="http://secunia.com/advisories/34852" source="SECUNIA" adv="1">34852</ref>
      <ref url="http://secunia.com/advisories/34756" source="SECUNIA" adv="1">34756</ref>
      <ref url="http://secunia.com/advisories/34755" source="SECUNIA" adv="1">34755</ref>
      <ref url="http://secunia.com/advisories/34481" source="SECUNIA" adv="1">34481</ref>
      <ref url="http://secunia.com/advisories/34291" source="SECUNIA" adv="1">34291</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0458.html" source="REDHAT">RHSA-2009:0458</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9941" source="OVAL">oval:org.mitre.oval:def:9941</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.html" source="SUSE">SUSE-SA:2009:024</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=263028" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=263028</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.10-1"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19" edition="rc1"/>
        <vers num="1.1.19" edition="rc2"/>
        <vers num="1.1.19" edition="rc3"/>
        <vers num="1.1.19" edition="rc4"/>
        <vers num="1.1.19" edition="rc5"/>
        <vers num="1.1.2"/>
        <vers num="1.1.20" edition="rc1"/>
        <vers num="1.1.20" edition="rc2"/>
        <vers num="1.1.20" edition="rc3"/>
        <vers num="1.1.20" edition="rc4"/>
        <vers num="1.1.20" edition="rc5"/>
        <vers num="1.1.20" edition="rc6"/>
        <vers num="1.1.21" edition="rc1"/>
        <vers num="1.1.21" edition="rc2"/>
        <vers num="1.1.22" edition="rc1"/>
        <vers num="1.1.22" edition="rc2"/>
        <vers num="1.1.23" edition="rc1"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.5-1"/>
        <vers num="1.1.5-2"/>
        <vers num="1.1.6"/>
        <vers num="1.1.6-1"/>
        <vers num="1.1.6-2"/>
        <vers num="1.1.6-3"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.1.9-1"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.10"/>
        <vers num="1.2.11"/>
        <vers num="1.2.12"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.2.8"/>
        <vers num="1.2.9"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.10"/>
        <vers num="1.3.11"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.5"/>
        <vers num="1.3.6"/>
        <vers num="1.3.7"/>
        <vers num="1.3.8"/>
        <vers prev="1" num="1.3.9"/>
      </prod>
      <prod vendor="foolabs" name="xpdf">
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.5a"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7a"/>
        <vers num="0.80"/>
        <vers num="0.90"/>
        <vers num="0.91"/>
        <vers num="0.91a"/>
        <vers num="0.91b"/>
        <vers num="0.91c"/>
        <vers num="0.92"/>
        <vers num="0.92a"/>
        <vers num="0.92b"/>
        <vers num="0.92c"/>
        <vers num="0.92d"/>
        <vers num="0.92e"/>
        <vers num="0.93"/>
        <vers num="0.93a"/>
        <vers num="0.93b"/>
        <vers num="0.93c"/>
        <vers num="1.00"/>
        <vers num="1.00a"/>
        <vers num="1.01"/>
        <vers num="2.00"/>
        <vers num="2.01"/>
        <vers num="2.02"/>
        <vers num="2.03"/>
        <vers num="3.00"/>
        <vers num="3.01"/>
        <vers prev="1" num="3.02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0148" published="2009-05-05" name="CVE-2009-0148" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple buffer overflows in Cscope before 15.7a allow remote attackers to execute arbitrary code via long strings in input such as (1) source-code tokens and (2) pathnames, related to integer overflows in some cases. NOTE: this issue exists because of an incomplete fix for CVE-2004-2541.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=4664&amp;release_id=679527" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=4664&amp;release_id=679527</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=947983" source="CONFIRM" patch="1">http://sourceforge.net/forum/forum.php?forum_id=947983</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=490667" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=490667</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN" adv="1">ADV-2009-1297</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1238" source="VUPEN" adv="1">ADV-2009-1238</ref>
      <ref url="http://www.securitytracker.com/id?1022218" source="SECTRACK">1022218</ref>
      <ref url="http://www.securityfocus.com/bid/34805" source="BID">34805</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1102.html" source="REDHAT">RHSA-2009:1102</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1101.html" source="REDHAT">RHSA-2009:1101</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/06/9" source="MLIST">[oss-security] 20090506 Re: Old cscope buffer overflow</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1806" source="DEBIAN">DSA-1806</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://sourceforge.net/mailarchive/forum.php?thread_name=E1LsGx3-00015K-TN%40ddv4jf1.ch3.sourceforge.com&amp;forum_name=cscope-cvs" source="MLIST">[cscope-cvs] 20090410 CVS: cscope/src snprintf.c, NONE, 1.1 build.c, 1.14, 1.15 command.c, 1.32, 1.33 dir.c, 1.30, 1.31 display.c, 1.29, 1.30 edit.c, 1.6, 1.7 exec.c, 1.11, 1.12 find.c, 1.20, 1.21 global.h, 1.36, 1.37 main.c, 1.45, 1.46 Makefile.am, 1.12, 1.13 Makefile.in, 1.15, 1.16 vpaccess.c, 1.2, 1.3 vpfopen.c, 1.3, 1.4 vpopen.c, 1.4, 1.5</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200905-02.xml" source="GENTOO">GLSA-200905-02</ref>
      <ref url="http://secunia.com/advisories/35462" source="SECUNIA" adv="1">35462</ref>
      <ref url="http://secunia.com/advisories/35214" source="SECUNIA" adv="1">35214</ref>
      <ref url="http://secunia.com/advisories/35213" source="SECUNIA" adv="1">35213</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA" adv="1">35074</ref>
      <ref url="http://secunia.com/advisories/34978" source="SECUNIA" adv="1">34978</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9633" source="OVAL">oval:org.mitre.oval:def:9633</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cscope" name="cscope">
        <vers num="13.0"/>
        <vers num="15.0bl2"/>
        <vers num="15.1"/>
        <vers num="15.3"/>
        <vers num="15.4"/>
        <vers num="15.5"/>
        <vers num="15.6"/>
        <vers num="15.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0149" published="2009-05-13" name="CVE-2009-0149" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows local users to gain privileges or cause a denial of service (application crash) by attempting to mount a crafted sparse disk image that triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50484" source="XF">macos-diskimages-code-execution-var1(50484)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securitytracker.com/id?1022217" source="SECTRACK">1022217</ref>
      <ref url="http://www.securityfocus.com/bid/34942" source="BID">34942</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0150" published="2009-05-13" name="CVE-2009-0150" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Apple Mac OS X 10.5 before 10.5.7 allows local users to gain privileges or cause a denial of service (application crash) by attempting to mount a crafted sparse disk image.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50483" source="XF">macos-diskimages-bo(50483)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securitytracker.com/id?1022217" source="SECTRACK">1022217</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0151" published="2009-08-06" name="CVE-2009-0151" modified="2009-08-19" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The screen saver in Dock in Apple Mac OS X 10.5 before 10.5.8 does not prevent four-finger Multi-Touch gestures, which allows physically proximate attackers to bypass locking and "manage applications or use Expose" via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-218A.html" source="CERT">TA09-218A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2172" source="VUPEN" patch="1" adv="1">ADV-2009-2172</ref>
      <ref url="http://www.securityfocus.com/bid/35954" source="BID" patch="1">35954</ref>
      <ref url="http://support.apple.com/kb/HT3757" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3757</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-08-05-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/52421" source="XF">macosx-dock-security-bypass(52421)</ref>
      <ref url="http://secunia.com/advisories/36096" source="SECUNIA" adv="1">36096</ref>
      <ref url="http://osvdb.org/56847" source="OSVDB">56847</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5"/>
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2" edition="2008-002"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
        <vers num="10.5.7"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5"/>
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
        <vers num="10.5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0152" published="2009-05-13" name="CVE-2009-0152" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">iChat in Apple Mac OS X 10.5 before 10.5.7 disables SSL for AOL Instant Messenger (AIM) communication in certain circumstances that are inconsistent with the Require SSL setting, which allows remote attackers to obtain sensitive information by sniffing the network.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50487" source="XF">macos-ichat-ssl-weak-security(50487)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securitytracker.com/id?1022212" source="SECTRACK">1022212</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0153" published="2009-05-13" name="CVE-2009-0153" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">International Components for Unicode (ICU) 4.0, 3.6, and other 3.x versions, as used in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Fedora 9 and 10, and possibly other operating systems, does not properly handle invalid byte sequences during Unicode conversion, which might allow remote attackers to conduct cross-site scripting (XSS) attacks.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00478.html" source="FEDORA">FEDORA-2009-6273</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00336.html" source="FEDORA">FEDORA-2009-6121</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=503071" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=503071</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50488" source="XF">macos-icu-security-bypass(50488)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN">ADV-2009-1522</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securityfocus.com/bid/34974" source="BID">34974</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1122.html" source="REDHAT">RHSA-2009:1122</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://secunia.com/advisories/35584" source="SECUNIA">35584</ref>
      <ref url="http://secunia.com/advisories/35498" source="SECUNIA">35498</ref>
      <ref url="http://secunia.com/advisories/35436" source="SECUNIA">35436</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA">35379</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11366" source="OVAL">oval:org.mitre.oval:def:11366</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://bugs.icu-project.org/trac/ticket/5691" source="CONFIRM">http://bugs.icu-project.org/trac/ticket/5691</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0154" published="2009-05-13" name="CVE-2009-0154" modified="2009-05-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code via a crafted Compact Font Format (CFF) font.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50478" source="XF">macos-ats-cff-bo(50478)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-023" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-023</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securitytracker.com/id?1022218" source="SECTRACK">1022218</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503597/100/0/threaded" source="BUGTRAQ">20090519 ZDI-09-023: Apple OS X ATSServer Compact Font Format Parsing Memory Corruption Vulnerability</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0155" published="2009-05-13" name="CVE-2009-0155" modified="2009-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer underflow in CoreGraphics in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF file that triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50482" source="XF">macos-coregraphics-pdf-bo(50482)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securitytracker.com/id?1022209" source="SECTRACK">1022209</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0156" published="2009-05-13" name="CVE-2009-0156" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Launch Services in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to cause a denial of service (persistent Finder crash) via a crafted Mach-O executable that triggers an out-of-bounds memory read.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50490" source="XF">macos-launchservices-dos(50490)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securitytracker.com/id?1022215" source="SECTRACK">1022215</ref>
      <ref url="http://www.securityfocus.com/bid/34932" source="BID">34932</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0157" published="2009-05-13" name="CVE-2009-0157" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in CFNetwork in Apple Mac OS X 10.5 before 10.5.7 allows remote web servers to execute arbitrary code or cause a denial of service (application crash) via long HTTP headers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50480" source="XF">macos-cfnetwork-bo(50480)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securitytracker.com/id?1022211" source="SECTRACK">1022211</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0158" published="2009-05-13" name="CVE-2009-0158" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in telnet in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long hostname for a telnet server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0159" published="2009-04-14" name="CVE-2009-0159" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the cookedprint function in ntpq/ntpq.c in ntpq in NTP before 4.2.4p7-RC2 allows remote NTP servers to execute arbitrary code via a crafted response.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="https://support.ntp.org/bugs/show_bug.cgi?id=1144" source="CONFIRM" patch="1">https://support.ntp.org/bugs/show_bug.cgi?id=1144</ref>
      <ref url="http://www.securityfocus.com/bid/34481" source="BID" patch="1">34481</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01449.html" source="FEDORA">FEDORA-2009-5275</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01414.html" source="FEDORA">FEDORA-2009-5273</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1651.html" source="REDHAT">RHSA-2009:1651</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=490617" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=490617</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49838" source="XF">ntp-cookedprint-bo(49838)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN" adv="1">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN" adv="1">ADV-2009-1297</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0999" source="VUPEN" adv="1">ADV-2009-0999</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-777-1" source="UBUNTU">USN-777-1</ref>
      <ref url="http://www.securitytracker.com/id?1022033" source="SECTRACK">1022033</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:092" source="MANDRIVA">MDVSA-2009:092</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200905-08.xml" source="GENTOO">GLSA-200905-08</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1801" source="DEBIAN">DSA-1801</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.566238" source="SLACKWARE">SSA:2009-154-01</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA" adv="1">37471</ref>
      <ref url="http://secunia.com/advisories/35630" source="SECUNIA" adv="1">35630</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA" adv="1">35416</ref>
      <ref url="http://secunia.com/advisories/35336" source="SECUNIA" adv="1">35336</ref>
      <ref url="http://secunia.com/advisories/35308" source="SECUNIA" adv="1">35308</ref>
      <ref url="http://secunia.com/advisories/35253" source="SECUNIA" adv="1">35253</ref>
      <ref url="http://secunia.com/advisories/35169" source="SECUNIA" adv="1">35169</ref>
      <ref url="http://secunia.com/advisories/35166" source="SECUNIA" adv="1">35166</ref>
      <ref url="http://secunia.com/advisories/35138" source="SECUNIA" adv="1">35138</ref>
      <ref url="http://secunia.com/advisories/35137" source="SECUNIA" adv="1">35137</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA" adv="1">35074</ref>
      <ref url="http://secunia.com/advisories/34608" source="SECUNIA" adv="1">34608</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-1040.html" source="REDHAT">RHSA-2009:1040</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-1039.html" source="REDHAT">RHSA-2009:1039</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9634" source="OVAL">oval:org.mitre.oval:def:9634</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8665" source="OVAL">oval:org.mitre.oval:def:8665</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8386" source="OVAL">oval:org.mitre.oval:def:8386</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5411" source="OVAL">oval:org.mitre.oval:def:5411</ref>
      <ref url="http://osvdb.org/53593" source="OSVDB">53593</ref>
      <ref url="http://ntp.bkbits.net:8080/ntp-stable/?PAGE=gnupatch&amp;REV=1.1565" source="CONFIRM">http://ntp.bkbits.net:8080/ntp-stable/?PAGE=gnupatch&amp;REV=1.1565</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136482797910018&amp;w=2" source="HP">SSRT101144</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136482797910018&amp;w=2" source="HP">HPSBUX02859</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
      <ref url="http://bugs.pardus.org.tr/show_bug.cgi?id=9532" source="CONFIRM">http://bugs.pardus.org.tr/show_bug.cgi?id=9532</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-006.txt.asc" source="NETBSD">NetBSD-SA2009-006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ntp" name="ntp">
        <vers num="4.0.72"/>
        <vers num="4.0.73"/>
        <vers num="4.0.90"/>
        <vers num="4.0.91"/>
        <vers num="4.0.92"/>
        <vers num="4.0.93"/>
        <vers num="4.0.94"/>
        <vers num="4.0.95"/>
        <vers num="4.0.96"/>
        <vers num="4.0.97"/>
        <vers num="4.0.98"/>
        <vers num="4.0.99"/>
        <vers num="4.1.0"/>
        <vers num="4.1.2"/>
        <vers num="4.2.0"/>
        <vers num="4.2.2"/>
        <vers num="4.2.2p1"/>
        <vers num="4.2.2p2"/>
        <vers num="4.2.2p3"/>
        <vers num="4.2.2p4"/>
        <vers num="4.2.4"/>
        <vers num="4.2.4p0"/>
        <vers num="4.2.4p1"/>
        <vers num="4.2.4p2"/>
        <vers num="4.2.4p3"/>
        <vers num="4.2.4p4"/>
        <vers num="4.2.4p5"/>
        <vers num="4.2.4p6"/>
        <vers prev="1" num="4.2.4p7" edition="rc1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0160" published="2009-05-13" name="CVE-2009-0160" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image that triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securitytracker.com/id?1022209" source="SECTRACK">1022209</ref>
      <ref url="http://www.securityfocus.com/bid/34937" source="BID">34937</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11"/>
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0161" published="2009-05-13" name="CVE-2009-0161" modified="2009-05-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The OpenSSL::OCSP module for Ruby in Apple Mac OS X 10.5 before 10.5.7 misinterprets an unspecified invalid response as a successful OCSP certificate validation, which might allow remote attackers to spoof certificate authentication via a revoked certificate.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50592" source="XF">macos-opensslocsp-weak-security(50592)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11"/>
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0162" published="2009-05-13" name="CVE-2009-0162" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Safari before 3.2.3, and 4 Public Beta, on Apple Mac OS X 10.5 before 10.5.7 and Windows allows remote attackers to inject arbitrary web script or HTML via a crafted feed: URL.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50476" source="XF">safari-feedurl-code-execution(50476)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1298" source="VUPEN">ADV-2009-1298</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securitytracker.com/id?1022206" source="SECTRACK">1022206</ref>
      <ref url="http://www.securityfocus.com/bid/34925" source="BID">34925</ref>
      <ref url="http://support.apple.com/kb/HT3550" source="CONFIRM">http://support.apple.com/kb/HT3550</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://secunia.com/advisories/35056" source="SECUNIA">35056</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.1"/>
        <vers num="3.1.0"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers prev="1" num="3.2.2"/>
        <vers num="4.0" edition="beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0163" published="2009-04-23" name="CVE-2009-0163" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and earlier allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a crafted TIFF image, which is not properly handled by the (1) _cupsImageReadTIFF function in the imagetops filter and (2) imagetoraster filter, leading to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=490596" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=490596</ref>
      <ref url="http://www.ubuntu.com/usn/usn-760-1" source="UBUNTU">USN-760-1</ref>
      <ref url="http://www.securitytracker.com/id?1022070" source="SECTRACK">1022070</ref>
      <ref url="http://www.securityfocus.com/bid/34571" source="BID">34571</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502750/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0061-1 cups</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0429.html" source="REDHAT">RHSA-2009:0429</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0428.html" source="REDHAT">RHSA-2009:0428</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1773" source="DEBIAN">DSA-1773</ref>
      <ref url="http://www.cups.org/str.php?L3031" source="CONFIRM">http://www.cups.org/str.php?L3031</ref>
      <ref url="http://www.cups.org/articles.php?L582" source="CONFIRM">http://www.cups.org/articles.php?L582</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0061" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0061</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-20.xml" source="GENTOO">GLSA-200904-20</ref>
      <ref url="http://secunia.com/advisories/34852" source="SECUNIA" adv="1">34852</ref>
      <ref url="http://secunia.com/advisories/34756" source="SECUNIA" adv="1">34756</ref>
      <ref url="http://secunia.com/advisories/34747" source="SECUNIA" adv="1">34747</ref>
      <ref url="http://secunia.com/advisories/34722" source="SECUNIA" adv="1">34722</ref>
      <ref url="http://secunia.com/advisories/34481" source="SECUNIA" adv="1">34481</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11546" source="OVAL">oval:org.mitre.oval:def:11546</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.html" source="SUSE">SUSE-SA:2009:024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.10-1"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19" edition="rc1"/>
        <vers num="1.1.19" edition="rc2"/>
        <vers num="1.1.19" edition="rc3"/>
        <vers num="1.1.19" edition="rc4"/>
        <vers num="1.1.19" edition="rc5"/>
        <vers num="1.1.2"/>
        <vers num="1.1.20" edition="rc1"/>
        <vers num="1.1.20" edition="rc2"/>
        <vers num="1.1.20" edition="rc3"/>
        <vers num="1.1.20" edition="rc4"/>
        <vers num="1.1.20" edition="rc5"/>
        <vers num="1.1.20" edition="rc6"/>
        <vers num="1.1.21" edition="rc1"/>
        <vers num="1.1.21" edition="rc2"/>
        <vers num="1.1.22" edition="rc1"/>
        <vers num="1.1.22" edition="rc2"/>
        <vers num="1.1.23" edition="rc1"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.5-1"/>
        <vers num="1.1.5-2"/>
        <vers num="1.1.6"/>
        <vers num="1.1.6-1"/>
        <vers num="1.1.6-2"/>
        <vers num="1.1.6-3"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.1.9-1"/>
        <vers num="1.2" edition="b1"/>
        <vers num="1.2" edition="b2"/>
        <vers num="1.2" edition="rc1"/>
        <vers num="1.2" edition="rc2"/>
        <vers num="1.2" edition="rc3"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.10"/>
        <vers num="1.2.11"/>
        <vers num="1.2.12"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.2.8"/>
        <vers num="1.2.9"/>
        <vers num="1.3" edition="b1"/>
        <vers num="1.3" edition="rc1"/>
        <vers num="1.3" edition="rc2"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.5"/>
        <vers num="1.3.6"/>
        <vers num="1.3.7"/>
        <vers num="1.3.8"/>
        <vers prev="1" num="1.3.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0164" published="2009-04-24" name="CVE-2009-0164" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The web interface for CUPS before 1.3.10 does not validate the HTTP Host header in a client request, which makes it easier for remote attackers to conduct DNS rebinding attacks.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=490597" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=490597</ref>
      <ref url="http://www.cups.org/str.php?L3118" source="CONFIRM" patch="1" adv="1">http://www.cups.org/str.php?L3118</ref>
      <ref url="http://www.cups.org/articles.php?L582" source="CONFIRM" patch="1" adv="1">http://www.cups.org/articles.php?L582</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securityfocus.com/bid/34665" source="BID">34665</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502750/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0061-1 cups</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0061" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0061</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-20.xml" source="GENTOO">GLSA-200904-20</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=263070" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=263070</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.10-1"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19" edition="rc1"/>
        <vers num="1.1.19" edition="rc2"/>
        <vers num="1.1.19" edition="rc3"/>
        <vers num="1.1.19" edition="rc4"/>
        <vers num="1.1.19" edition="rc5"/>
        <vers num="1.1.2"/>
        <vers num="1.1.20" edition="rc1"/>
        <vers num="1.1.20" edition="rc2"/>
        <vers num="1.1.20" edition="rc3"/>
        <vers num="1.1.20" edition="rc4"/>
        <vers num="1.1.20" edition="rc5"/>
        <vers num="1.1.20" edition="rc6"/>
        <vers num="1.1.21" edition="rc1"/>
        <vers num="1.1.21" edition="rc2"/>
        <vers num="1.1.22" edition="rc1"/>
        <vers num="1.1.22" edition="rc2"/>
        <vers num="1.1.23" edition="rc1"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.5-1"/>
        <vers num="1.1.5-2"/>
        <vers num="1.1.6"/>
        <vers num="1.1.6-1"/>
        <vers num="1.1.6-2"/>
        <vers num="1.1.6-3"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.1.9-1"/>
        <vers num="1.2" edition="b1"/>
        <vers num="1.2" edition="b2"/>
        <vers num="1.2" edition="rc1"/>
        <vers num="1.2" edition="rc2"/>
        <vers num="1.2" edition="rc3"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.10"/>
        <vers num="1.2.11"/>
        <vers num="1.2.12"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.2.8"/>
        <vers num="1.2.9"/>
        <vers num="1.3" edition="b1"/>
        <vers num="1.3" edition="rc1"/>
        <vers num="1.3" edition="rc2"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.5"/>
        <vers num="1.3.6"/>
        <vers num="1.3.7"/>
        <vers num="1.3.8"/>
        <vers prev="1" num="1.3.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0165" published="2009-04-23" name="CVE-2009-0165" modified="2009-07-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unspecified impact, related to "g*allocn."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=263028" source="CONFIRM" patch="1">http://bugs.gentoo.org/show_bug.cgi?id=263028</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50377" source="XF">multiple-jbig2-unspecified(50377)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securityfocus.com/bid/34568" source="BID">34568</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:101" source="MANDRIVA">MDVSA-2009:101</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1793" source="DEBIAN">DSA-1793</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1790" source="DEBIAN">DSA-1790</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.578477" source="SLACKWARE">SSA:2009-129-01</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA">35065</ref>
      <ref url="http://secunia.com/advisories/35037" source="SECUNIA">35037</ref>
      <ref url="http://secunia.com/advisories/34991" source="SECUNIA">34991</ref>
      <ref url="http://secunia.com/advisories/34959" source="SECUNIA">34959</ref>
      <ref url="http://secunia.com/advisories/34852" source="SECUNIA">34852</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.html" source="SUSE">SUSE-SA:2009:024</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="foolabs" name="xpdf">
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.5a"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7a"/>
        <vers num="0.80"/>
        <vers num="0.90"/>
        <vers num="0.91"/>
        <vers num="0.91a"/>
        <vers num="0.91b"/>
        <vers num="0.91c"/>
        <vers num="0.92"/>
        <vers num="0.92a"/>
        <vers num="0.92b"/>
        <vers num="0.92c"/>
        <vers num="0.92d"/>
        <vers num="0.92e"/>
        <vers num="0.93"/>
        <vers num="0.93a"/>
        <vers num="0.93b"/>
        <vers num="0.93c"/>
        <vers num="1.00"/>
        <vers num="1.00a"/>
        <vers num="1.01"/>
        <vers num="2.00"/>
        <vers num="2.01"/>
        <vers num="2.02"/>
        <vers num="2.03"/>
        <vers num="3.0.1"/>
        <vers num="3.00"/>
        <vers num="3.01"/>
        <vers prev="1" num="3.02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0166" published="2009-04-23" name="CVE-2009-0166" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a free of uninitialized memory.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1066" source="VUPEN" patch="1" adv="1">ADV-2009-1066</ref>
      <ref url="http://www.securityfocus.com/bid/34568" source="BID" patch="1">34568</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0480.html" source="REDHAT" patch="1">RHSA-2009:0480</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0431.html" source="REDHAT" patch="1">RHSA-2009:0431</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0430.html" source="REDHAT" patch="1">RHSA-2009:0430</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0429.html" source="REDHAT" patch="1">RHSA-2009:0429</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1793" source="DEBIAN" patch="1">DSA-1793</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1790" source="DEBIAN" patch="1">DSA-1790</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0458.html" source="REDHAT" patch="1">RHSA-2009:0458</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01291.html" source="FEDORA">FEDORA-2009-6982</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01277.html" source="FEDORA">FEDORA-2009-6973</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00567.html" source="FEDORA">FEDORA-2009-6972</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=490625" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=490625</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1040" source="VUPEN" adv="1">ADV-2010-1040</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1077" source="VUPEN" adv="1">ADV-2009-1077</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1065" source="VUPEN" adv="1">ADV-2009-1065</ref>
      <ref url="http://www.securitytracker.com/id?1022073" source="SECTRACK">1022073</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502750/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0061-1 cups</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:087" source="MANDRIVA">MDVSA-2010:087</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:101" source="MANDRIVA">MDVSA-2009:101</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0061" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0061</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.578477" source="SLACKWARE">SSA:2009-129-01</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-20.xml" source="GENTOO">GLSA-200904-20</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA" adv="1">35685</ref>
      <ref url="http://secunia.com/advisories/35618" source="SECUNIA" adv="1">35618</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA" adv="1">35065</ref>
      <ref url="http://secunia.com/advisories/35064" source="SECUNIA" adv="1">35064</ref>
      <ref url="http://secunia.com/advisories/35037" source="SECUNIA" adv="1">35037</ref>
      <ref url="http://secunia.com/advisories/34991" source="SECUNIA" adv="1">34991</ref>
      <ref url="http://secunia.com/advisories/34963" source="SECUNIA" adv="1">34963</ref>
      <ref url="http://secunia.com/advisories/34959" source="SECUNIA" adv="1">34959</ref>
      <ref url="http://secunia.com/advisories/34852" source="SECUNIA" adv="1">34852</ref>
      <ref url="http://secunia.com/advisories/34756" source="SECUNIA" adv="1">34756</ref>
      <ref url="http://secunia.com/advisories/34755" source="SECUNIA" adv="1">34755</ref>
      <ref url="http://secunia.com/advisories/34481" source="SECUNIA" adv="1">34481</ref>
      <ref url="http://secunia.com/advisories/34291" source="SECUNIA" adv="1">34291</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9778" source="OVAL">oval:org.mitre.oval:def:9778</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.html" source="SUSE">SUSE-SA:2009:024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.10-1"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19" edition="rc1"/>
        <vers num="1.1.19" edition="rc2"/>
        <vers num="1.1.19" edition="rc3"/>
        <vers num="1.1.19" edition="rc4"/>
        <vers num="1.1.19" edition="rc5"/>
        <vers num="1.1.2"/>
        <vers num="1.1.20" edition="rc1"/>
        <vers num="1.1.20" edition="rc2"/>
        <vers num="1.1.20" edition="rc3"/>
        <vers num="1.1.20" edition="rc4"/>
        <vers num="1.1.20" edition="rc5"/>
        <vers num="1.1.20" edition="rc6"/>
        <vers num="1.1.21" edition="rc1"/>
        <vers num="1.1.21" edition="rc2"/>
        <vers num="1.1.22" edition="rc1"/>
        <vers num="1.1.22" edition="rc2"/>
        <vers num="1.1.23" edition="rc1"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.5-1"/>
        <vers num="1.1.5-2"/>
        <vers num="1.1.6"/>
        <vers num="1.1.6-1"/>
        <vers num="1.1.6-2"/>
        <vers num="1.1.6-3"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.1.9-1"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.10"/>
        <vers num="1.2.11"/>
        <vers num="1.2.12"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.2.8"/>
        <vers num="1.2.9"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.10"/>
        <vers num="1.3.11"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.5"/>
        <vers num="1.3.6"/>
        <vers num="1.3.7"/>
        <vers num="1.3.8"/>
        <vers prev="1" num="1.3.9"/>
      </prod>
      <prod vendor="foolabs" name="xpdf">
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.5a"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7a"/>
        <vers num="0.80"/>
        <vers num="0.90"/>
        <vers num="0.91"/>
        <vers num="0.91a"/>
        <vers num="0.91b"/>
        <vers num="0.91c"/>
        <vers num="0.92"/>
        <vers num="0.92a"/>
        <vers num="0.92b"/>
        <vers num="0.92c"/>
        <vers num="0.92d"/>
        <vers num="0.92e"/>
        <vers num="0.93"/>
        <vers num="0.93a"/>
        <vers num="0.93b"/>
        <vers num="0.93c"/>
        <vers num="1.00"/>
        <vers num="1.00a"/>
        <vers num="1.01"/>
        <vers num="2.00"/>
        <vers num="2.01"/>
        <vers num="2.02"/>
        <vers num="2.03"/>
        <vers num="3.00"/>
        <vers num="3.01"/>
        <vers prev="1" num="3.02"/>
      </prod>
      <prod vendor="poppler" name="poppler">
        <vers num="0.1"/>
        <vers num="0.1.1"/>
        <vers num="0.1.2"/>
        <vers num="0.10.0"/>
        <vers num="0.10.1"/>
        <vers num="0.10.2"/>
        <vers num="0.10.3"/>
        <vers num="0.10.4"/>
        <vers prev="1" num="0.10.5"/>
        <vers num="0.2.0"/>
        <vers num="0.3.0"/>
        <vers num="0.3.1"/>
        <vers num="0.3.2"/>
        <vers num="0.3.3"/>
        <vers num="0.4.0"/>
        <vers num="0.4.1"/>
        <vers num="0.4.2"/>
        <vers num="0.4.3"/>
        <vers num="0.4.4"/>
        <vers num="0.5.0"/>
        <vers num="0.5.1"/>
        <vers num="0.5.2"/>
        <vers num="0.5.3"/>
        <vers num="0.5.4"/>
        <vers num="0.5.9"/>
        <vers num="0.5.90"/>
        <vers num="0.5.91"/>
        <vers num="0.6.0"/>
        <vers num="0.6.1"/>
        <vers num="0.6.2"/>
        <vers num="0.6.3"/>
        <vers num="0.6.4"/>
        <vers num="0.7.0"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.8.0"/>
        <vers num="0.8.1"/>
        <vers num="0.8.2"/>
        <vers num="0.8.3"/>
        <vers num="0.8.4"/>
        <vers num="0.8.5"/>
        <vers num="0.8.6"/>
        <vers num="0.8.7"/>
        <vers num="0.9.0"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0167" published="2009-01-16" name="CVE-2009-0167" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">Unspecified vulnerability in lpadmin in Sun Solaris 10 and OpenSolaris snv_61 through snv_106 allows local users to cause a denial of service via unspecified vectors, related to enumeration of "wrong printers," aka a "Temporary file vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-139390-01-1" source="CONFIRM" patch="1" adv="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-139390-01-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0155" source="VUPEN">ADV-2009-0155</ref>
      <ref url="http://www.securitytracker.com/id?1021601" source="SECTRACK">1021601</ref>
      <ref url="http://www.securityfocus.com/bid/33269" source="BID">33269</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-026.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-026.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-249306-1" source="SUNALERT" adv="1">249306</ref>
      <ref url="http://secunia.com/advisories/33705" source="SECUNIA">33705</ref>
      <ref url="http://secunia.com/advisories/33488" source="SECUNIA">33488</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6175" source="OVAL">oval:org.mitre.oval:def:6175</ref>
      <ref url="http://opensolaris.org/os/bug_reports/request_sponsor/" source="MISC">http://opensolaris.org/os/bug_reports/request_sponsor/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_100" edition=""/>
        <vers num="snv_100" edition=":x86"/>
        <vers num="snv_100" edition=":sparc"/>
        <vers num="snv_101" edition=""/>
        <vers num="snv_101" edition=":x86"/>
        <vers num="snv_101" edition=":sparc"/>
        <vers num="snv_102" edition=""/>
        <vers num="snv_102" edition=":x86"/>
        <vers num="snv_102" edition=":sparc"/>
        <vers num="snv_103" edition=""/>
        <vers num="snv_103" edition=":sparc"/>
        <vers num="snv_103" edition=":x86"/>
        <vers num="snv_104" edition=""/>
        <vers num="snv_104" edition=":sparc"/>
        <vers num="snv_104" edition=":x86"/>
        <vers num="snv_105" edition=""/>
        <vers num="snv_105" edition=":x86"/>
        <vers num="snv_105" edition=":sparc"/>
        <vers num="snv_106" edition=""/>
        <vers num="snv_106" edition=":sparc"/>
        <vers num="snv_106" edition=":x86"/>
        <vers num="snv_61" edition=""/>
        <vers num="snv_61" edition=":sparc"/>
        <vers num="snv_61" edition=":x86"/>
        <vers num="snv_62" edition=""/>
        <vers num="snv_62" edition=":x86"/>
        <vers num="snv_62" edition=":sparc"/>
        <vers num="snv_63" edition=""/>
        <vers num="snv_63" edition=":sparc"/>
        <vers num="snv_63" edition=":x86"/>
        <vers num="snv_64" edition=""/>
        <vers num="snv_64" edition=":x86"/>
        <vers num="snv_64" edition=":sparc"/>
        <vers num="snv_65" edition=""/>
        <vers num="snv_65" edition=":sparc"/>
        <vers num="snv_65" edition=":x86"/>
        <vers num="snv_66" edition=""/>
        <vers num="snv_66" edition=":x86"/>
        <vers num="snv_66" edition=":sparc"/>
        <vers num="snv_67" edition=""/>
        <vers num="snv_67" edition=":sparc"/>
        <vers num="snv_67" edition=":x86"/>
        <vers num="snv_68" edition=""/>
        <vers num="snv_68" edition=":x86"/>
        <vers num="snv_68" edition=":sparc"/>
        <vers num="snv_69" edition=""/>
        <vers num="snv_69" edition=":x86"/>
        <vers num="snv_69" edition=":sparc"/>
        <vers num="snv_70" edition=""/>
        <vers num="snv_70" edition=":sparc"/>
        <vers num="snv_70" edition=":x86"/>
        <vers num="snv_71" edition=""/>
        <vers num="snv_71" edition=":sparc"/>
        <vers num="snv_71" edition=":x86"/>
        <vers num="snv_72" edition=""/>
        <vers num="snv_72" edition=":x86"/>
        <vers num="snv_72" edition=":sparc"/>
        <vers num="snv_73" edition=""/>
        <vers num="snv_73" edition=":sparc"/>
        <vers num="snv_73" edition=":x86"/>
        <vers num="snv_74" edition=""/>
        <vers num="snv_74" edition=":x86"/>
        <vers num="snv_74" edition=":sparc"/>
        <vers num="snv_75" edition=""/>
        <vers num="snv_75" edition=":x86"/>
        <vers num="snv_75" edition=":sparc"/>
        <vers num="snv_76" edition=""/>
        <vers num="snv_76" edition=":sparc"/>
        <vers num="snv_76" edition=":x86"/>
        <vers num="snv_77" edition=""/>
        <vers num="snv_77" edition=":sparc"/>
        <vers num="snv_77" edition=":x86"/>
        <vers num="snv_78" edition=""/>
        <vers num="snv_78" edition=":sparc"/>
        <vers num="snv_78" edition=":x86"/>
        <vers num="snv_79" edition=""/>
        <vers num="snv_79" edition=":x86"/>
        <vers num="snv_79" edition=":sparc"/>
        <vers num="snv_80" edition=""/>
        <vers num="snv_80" edition=":x86"/>
        <vers num="snv_80" edition=":sparc"/>
        <vers num="snv_81" edition=""/>
        <vers num="snv_81" edition=":x86"/>
        <vers num="snv_81" edition=":sparc"/>
        <vers num="snv_82" edition=""/>
        <vers num="snv_82" edition=":sparc"/>
        <vers num="snv_82" edition=":x86"/>
        <vers num="snv_83" edition=""/>
        <vers num="snv_83" edition=":sparc"/>
        <vers num="snv_83" edition=":x86"/>
        <vers num="snv_84" edition=""/>
        <vers num="snv_84" edition=":x86"/>
        <vers num="snv_84" edition=":sparc"/>
        <vers num="snv_85" edition=""/>
        <vers num="snv_85" edition=":sparc"/>
        <vers num="snv_85" edition=":x86"/>
        <vers num="snv_86" edition=""/>
        <vers num="snv_86" edition=":sparc"/>
        <vers num="snv_86" edition=":x86"/>
        <vers num="snv_87" edition=""/>
        <vers num="snv_87" edition=":sparc"/>
        <vers num="snv_87" edition=":x86"/>
        <vers num="snv_88" edition=""/>
        <vers num="snv_88" edition=":x86"/>
        <vers num="snv_88" edition=":sparc"/>
        <vers num="snv_89" edition=""/>
        <vers num="snv_89" edition=":x86"/>
        <vers num="snv_89" edition=":sparc"/>
        <vers num="snv_90" edition=""/>
        <vers num="snv_90" edition=":x86"/>
        <vers num="snv_90" edition=":sparc"/>
        <vers num="snv_91" edition=""/>
        <vers num="snv_91" edition=":x86"/>
        <vers num="snv_91" edition=":sparc"/>
        <vers num="snv_92" edition=""/>
        <vers num="snv_92" edition=":sparc"/>
        <vers num="snv_92" edition=":x86"/>
        <vers num="snv_93" edition=""/>
        <vers num="snv_93" edition=":sparc"/>
        <vers num="snv_93" edition=":x86"/>
        <vers num="snv_94" edition=""/>
        <vers num="snv_94" edition=":x86"/>
        <vers num="snv_94" edition=":sparc"/>
        <vers num="snv_95" edition=""/>
        <vers num="snv_95" edition=":sparc"/>
        <vers num="snv_95" edition=":x86"/>
        <vers num="snv_96" edition=""/>
        <vers num="snv_96" edition=":x86"/>
        <vers num="snv_96" edition=":sparc"/>
        <vers num="snv_97" edition=""/>
        <vers num="snv_97" edition=":x86"/>
        <vers num="snv_97" edition=":sparc"/>
        <vers num="snv_98" edition=""/>
        <vers num="snv_98" edition=":x86"/>
        <vers num="snv_98" edition=":sparc"/>
        <vers num="snv_99" edition=""/>
        <vers num="snv_99" edition=":sparc"/>
        <vers num="snv_99" edition=":x86"/>
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition=""/>
        <vers num="10.0" edition=":x86"/>
        <vers num="10.0" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0168" published="2009-01-16" name="CVE-2009-0168" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in ppdmgr in Sun Solaris 10 and OpenSolaris snv_61 through snv_106 allows local users to cause a denial of service via unspecified vectors, related to a failure to "include all cache files," and improper handling of temporary files.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-249306-1" source="SUNALERT" patch="1">249306</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-139390-01-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-139390-01-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48143" source="XF">solaris-ppdmgr-dos(48143)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0155" source="VUPEN">ADV-2009-0155</ref>
      <ref url="http://www.securitytracker.com/id?1021601" source="SECTRACK">1021601</ref>
      <ref url="http://www.securityfocus.com/bid/33269" source="BID">33269</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-026.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-026.htm</ref>
      <ref url="http://secunia.com/advisories/33705" source="SECUNIA">33705</ref>
      <ref url="http://secunia.com/advisories/33488" source="SECUNIA">33488</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5503" source="OVAL">oval:org.mitre.oval:def:5503</ref>
      <ref url="http://opensolaris.org/os/bug_reports/request_sponsor/" source="MISC">http://opensolaris.org/os/bug_reports/request_sponsor/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_100" edition=""/>
        <vers num="snv_100" edition=":x86"/>
        <vers num="snv_100" edition=":sparc"/>
        <vers num="snv_101" edition=""/>
        <vers num="snv_101" edition=":x86"/>
        <vers num="snv_101" edition=":sparc"/>
        <vers num="snv_102" edition=""/>
        <vers num="snv_102" edition=":x86"/>
        <vers num="snv_102" edition=":sparc"/>
        <vers num="snv_103" edition=""/>
        <vers num="snv_103" edition=":sparc"/>
        <vers num="snv_103" edition=":x86"/>
        <vers num="snv_104" edition=""/>
        <vers num="snv_104" edition=":sparc"/>
        <vers num="snv_104" edition=":x86"/>
        <vers num="snv_105" edition=""/>
        <vers num="snv_105" edition=":x86"/>
        <vers num="snv_105" edition=":sparc"/>
        <vers num="snv_106" edition=""/>
        <vers num="snv_106" edition=":sparc"/>
        <vers num="snv_106" edition=":x86"/>
        <vers num="snv_61" edition=""/>
        <vers num="snv_61" edition=":sparc"/>
        <vers num="snv_61" edition=":x86"/>
        <vers num="snv_62" edition=""/>
        <vers num="snv_62" edition=":x86"/>
        <vers num="snv_62" edition=":sparc"/>
        <vers num="snv_63" edition=""/>
        <vers num="snv_63" edition=":sparc"/>
        <vers num="snv_63" edition=":x86"/>
        <vers num="snv_64" edition=""/>
        <vers num="snv_64" edition=":x86"/>
        <vers num="snv_64" edition=":sparc"/>
        <vers num="snv_65" edition=""/>
        <vers num="snv_65" edition=":sparc"/>
        <vers num="snv_65" edition=":x86"/>
        <vers num="snv_66" edition=""/>
        <vers num="snv_66" edition=":x86"/>
        <vers num="snv_66" edition=":sparc"/>
        <vers num="snv_67" edition=""/>
        <vers num="snv_67" edition=":sparc"/>
        <vers num="snv_67" edition=":x86"/>
        <vers num="snv_68" edition=""/>
        <vers num="snv_68" edition=":x86"/>
        <vers num="snv_68" edition=":sparc"/>
        <vers num="snv_69" edition=""/>
        <vers num="snv_69" edition=":x86"/>
        <vers num="snv_69" edition=":sparc"/>
        <vers num="snv_70" edition=""/>
        <vers num="snv_70" edition=":sparc"/>
        <vers num="snv_70" edition=":x86"/>
        <vers num="snv_71" edition=""/>
        <vers num="snv_71" edition=":sparc"/>
        <vers num="snv_71" edition=":x86"/>
        <vers num="snv_72" edition=""/>
        <vers num="snv_72" edition=":x86"/>
        <vers num="snv_72" edition=":sparc"/>
        <vers num="snv_73" edition=""/>
        <vers num="snv_73" edition=":sparc"/>
        <vers num="snv_73" edition=":x86"/>
        <vers num="snv_74" edition=""/>
        <vers num="snv_74" edition=":x86"/>
        <vers num="snv_74" edition=":sparc"/>
        <vers num="snv_75" edition=""/>
        <vers num="snv_75" edition=":x86"/>
        <vers num="snv_75" edition=":sparc"/>
        <vers num="snv_76" edition=""/>
        <vers num="snv_76" edition=":sparc"/>
        <vers num="snv_76" edition=":x86"/>
        <vers num="snv_77" edition=""/>
        <vers num="snv_77" edition=":sparc"/>
        <vers num="snv_77" edition=":x86"/>
        <vers num="snv_78" edition=""/>
        <vers num="snv_78" edition=":sparc"/>
        <vers num="snv_78" edition=":x86"/>
        <vers num="snv_79" edition=""/>
        <vers num="snv_79" edition=":x86"/>
        <vers num="snv_79" edition=":sparc"/>
        <vers num="snv_80" edition=""/>
        <vers num="snv_80" edition=":x86"/>
        <vers num="snv_80" edition=":sparc"/>
        <vers num="snv_81" edition=""/>
        <vers num="snv_81" edition=":x86"/>
        <vers num="snv_81" edition=":sparc"/>
        <vers num="snv_82" edition=""/>
        <vers num="snv_82" edition=":sparc"/>
        <vers num="snv_82" edition=":x86"/>
        <vers num="snv_83" edition=""/>
        <vers num="snv_83" edition=":sparc"/>
        <vers num="snv_83" edition=":x86"/>
        <vers num="snv_84" edition=""/>
        <vers num="snv_84" edition=":x86"/>
        <vers num="snv_84" edition=":sparc"/>
        <vers num="snv_85" edition=""/>
        <vers num="snv_85" edition=":sparc"/>
        <vers num="snv_85" edition=":x86"/>
        <vers num="snv_86" edition=""/>
        <vers num="snv_86" edition=":sparc"/>
        <vers num="snv_86" edition=":x86"/>
        <vers num="snv_87" edition=""/>
        <vers num="snv_87" edition=":sparc"/>
        <vers num="snv_87" edition=":x86"/>
        <vers num="snv_88" edition=""/>
        <vers num="snv_88" edition=":x86"/>
        <vers num="snv_88" edition=":sparc"/>
        <vers num="snv_89" edition=""/>
        <vers num="snv_89" edition=":x86"/>
        <vers num="snv_89" edition=":sparc"/>
        <vers num="snv_90" edition=""/>
        <vers num="snv_90" edition=":x86"/>
        <vers num="snv_90" edition=":sparc"/>
        <vers num="snv_91" edition=""/>
        <vers num="snv_91" edition=":x86"/>
        <vers num="snv_91" edition=":sparc"/>
        <vers num="snv_92" edition=""/>
        <vers num="snv_92" edition=":sparc"/>
        <vers num="snv_92" edition=":x86"/>
        <vers num="snv_93" edition=""/>
        <vers num="snv_93" edition=":sparc"/>
        <vers num="snv_93" edition=":x86"/>
        <vers num="snv_94" edition=""/>
        <vers num="snv_94" edition=":x86"/>
        <vers num="snv_94" edition=":sparc"/>
        <vers num="snv_95" edition=""/>
        <vers num="snv_95" edition=":sparc"/>
        <vers num="snv_95" edition=":x86"/>
        <vers num="snv_96" edition=""/>
        <vers num="snv_96" edition=":x86"/>
        <vers num="snv_96" edition=":sparc"/>
        <vers num="snv_97" edition=""/>
        <vers num="snv_97" edition=":x86"/>
        <vers num="snv_97" edition=":sparc"/>
        <vers num="snv_98" edition=""/>
        <vers num="snv_98" edition=":x86"/>
        <vers num="snv_98" edition=":sparc"/>
        <vers num="snv_99" edition=""/>
        <vers num="snv_99" edition=":sparc"/>
        <vers num="snv_99" edition=":x86"/>
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10" edition=""/>
        <vers num="10" edition=":sparc"/>
        <vers num="10" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0169" published="2009-01-16" name="CVE-2009-0169" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Sun Java System Access Manager 7.1 allows remote authenticated sub-realm administrators to gain privileges, as demonstrated by creating the amadmin account in the sub-realm, and then logging in as amadmin in the root realm.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33266" source="BID" patch="1">33266</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-126356-02-1" source="CONFIRM" patch="1" adv="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-126356-02-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/47944" source="XF">sun-jsam-subrealm-privilege-escalation(47944)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0157" source="VUPEN">ADV-2009-0157</ref>
      <ref url="http://www.securitytracker.com/id?1021604" source="SECTRACK">1021604</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-249106-1" source="SUNALERT" adv="1">249106</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_access_manager">
        <vers num="7.1" edition=""/>
        <vers num="7.1" edition=":solaris_sparc"/>
        <vers num="7.1" edition=":windows"/>
        <vers num="7.1" edition=":linux"/>
        <vers num="7.1" edition=":solaris_x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0170" published="2009-01-16" name="CVE-2009-0170" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Sun Java System Access Manager 6.3 2005Q1, 7 2005Q4, and 7.1 allows remote authenticated users with console privileges to discover passwords, and obtain unspecified other "access to resources," by visiting the Configuration Items component in the console.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33265" source="BID" patch="1">33265</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-242166-1" source="SUNALERT" patch="1" adv="1">242166</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-126356-02-1" source="CONFIRM" patch="1" adv="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-126356-02-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/47942" source="XF">sun-jsam-password-info-disclosure(47942)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0156" source="VUPEN">ADV-2009-0156</ref>
      <ref url="http://www.securitytracker.com/id?1021605" source="SECTRACK">1021605</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_access_manager">
        <vers num="6.3_2005q4"/>
        <vers num="7.0_2005q4"/>
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0171" published="2009-01-16" name="CVE-2009-0171" modified="2011-06-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Sun SPARC Enterprise M4000 and M5000 Server, within a certain range of serial numbers, allows remote attackers to use the manufacturing root password, perform a root login to the eXtended System Control Facility Unit (aka XSCFU or Service Processor), and have unspecified other impact.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0207" source="VUPEN" adv="1">ADV-2009-0207</ref>
      <ref url="http://www.securitytracker.com/id?1021602" source="SECTRACK">1021602</ref>
      <ref url="http://www.securityfocus.com/bid/33280" source="BID">33280</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-249126-1" source="SUNALERT" adv="1">249126</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sparc_enterprise_server">
        <vers num="m4000"/>
        <vers num="m5000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0172" published="2009-01-16" name="CVE-2009-0172" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cause a denial of service (infinite loop) via a crafted CONNECT data stream.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33258" source="BID" patch="1">33258</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21363936" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21363936</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/47931" source="XF">ibm-db2-connect-stream-dos(47931)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0137" source="VUPEN">ADV-2009-0137</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IZ37696" source="AIXAPAR">IZ37696</ref>
      <ref url="http://securitytracker.com/id?1021591" source="SECTRACK">1021591</ref>
      <ref url="http://secunia.com/advisories/33529" source="SECUNIA" adv="1">33529</ref>
      <ref url="ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT" source="CONFIRM">ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT</ref>
      <ref url="ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v91/APARLIST.TXT" source="CONFIRM">ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v91/APARLIST.TXT</ref>
      <ref url="ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT" source="CONFIRM">ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2_universal_database">
        <vers num="9.1" edition=""/>
        <vers num="9.1" edition=":aix"/>
        <vers num="9.1" edition=":windows"/>
        <vers num="9.1" edition=":hp-ux"/>
        <vers num="9.1" edition=":solaris"/>
        <vers num="9.1" edition=":linux"/>
        <vers num="9.1" edition="fp2"/>
        <vers num="9.1" edition="fp2:linux"/>
        <vers num="9.1" edition="fp2:windows"/>
        <vers num="9.1" edition="fp2:hp-ux"/>
        <vers num="9.1" edition="fp2:aix"/>
        <vers num="9.1" edition="fp2:solaris"/>
        <vers num="9.1" edition="fp3"/>
        <vers num="9.1" edition="fp3:hp-ux"/>
        <vers num="9.1" edition="fp3:solaris"/>
        <vers num="9.1" edition="fp3:aix"/>
        <vers num="9.1" edition="fp4"/>
        <vers num="9.1" edition="fp4:linux"/>
        <vers num="9.1" edition="fp4:windows"/>
        <vers num="9.1" edition="fp4:aix"/>
        <vers num="9.1" edition="fp4:hp-ux"/>
        <vers num="9.1" edition="fp4a"/>
        <vers num="9.1" edition="fp4a:hp-ux"/>
        <vers num="9.1" edition="fp4a:linux"/>
        <vers num="9.1" edition="fp4a:windows"/>
        <vers num="9.1" edition="ga"/>
        <vers num="9.5" edition=""/>
        <vers num="9.5" edition=":linux"/>
        <vers num="9.5" edition=":windows"/>
        <vers num="9.5" edition=":hp-ux"/>
        <vers num="9.5" edition=":aix"/>
        <vers num="9.5" edition=":solaris"/>
        <vers num="9.5" edition="fp1"/>
        <vers num="9.5" edition="fp1:windows"/>
        <vers num="9.5" edition="fp1:hp-ux"/>
        <vers num="9.5" edition="fp1:aix"/>
        <vers num="9.5" edition="fp1:solaris"/>
        <vers num="9.5" edition="fp1:linux"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0173" published="2009-01-16" name="CVE-2009-0173" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the server in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote authenticated users to cause a denial of service (trap) via a crafted data stream.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21363936" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21363936</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/47934" source="XF">ibm-db2-datastream-dos(47934)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0137" source="VUPEN">ADV-2009-0137</ref>
      <ref url="http://www.securityfocus.com/bid/33258" source="BID">33258</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IZ39652" source="AIXAPAR">IZ39652</ref>
      <ref url="http://securitytracker.com/id?1021591" source="SECTRACK">1021591</ref>
      <ref url="http://secunia.com/advisories/33529" source="SECUNIA" adv="1">33529</ref>
      <ref url="ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT" source="CONFIRM">ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT</ref>
      <ref url="ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v91/APARLIST.TXT" source="CONFIRM">ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v91/APARLIST.TXT</ref>
      <ref url="ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT" source="CONFIRM">ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2_universal_database">
        <vers num="9.1" edition=""/>
        <vers num="9.1" edition=":aix"/>
        <vers num="9.1" edition=":windows"/>
        <vers num="9.1" edition=":hp-ux"/>
        <vers num="9.1" edition=":solaris"/>
        <vers num="9.1" edition=":linux"/>
        <vers num="9.1" edition="fp2"/>
        <vers num="9.1" edition="fp2:linux"/>
        <vers num="9.1" edition="fp2:windows"/>
        <vers num="9.1" edition="fp2:hp-ux"/>
        <vers num="9.1" edition="fp2:aix"/>
        <vers num="9.1" edition="fp2:solaris"/>
        <vers num="9.1" edition="fp3"/>
        <vers num="9.1" edition="fp3:hp-ux"/>
        <vers num="9.1" edition="fp3:solaris"/>
        <vers num="9.1" edition="fp3:aix"/>
        <vers num="9.1" edition="fp4"/>
        <vers num="9.1" edition="fp4:linux"/>
        <vers num="9.1" edition="fp4:windows"/>
        <vers num="9.1" edition="fp4:aix"/>
        <vers num="9.1" edition="fp4:hp-ux"/>
        <vers num="9.1" edition="fp4a"/>
        <vers num="9.1" edition="fp4a:hp-ux"/>
        <vers num="9.1" edition="fp4a:linux"/>
        <vers num="9.1" edition="fp4a:windows"/>
        <vers num="9.1" edition="ga"/>
        <vers num="9.5" edition=""/>
        <vers num="9.5" edition=":linux"/>
        <vers num="9.5" edition=":windows"/>
        <vers num="9.5" edition=":hp-ux"/>
        <vers num="9.5" edition=":aix"/>
        <vers num="9.5" edition=":solaris"/>
        <vers num="9.5" edition="fp1"/>
        <vers num="9.5" edition="fp1:windows"/>
        <vers num="9.5" edition="fp1:hp-ux"/>
        <vers num="9.5" edition="fp1:aix"/>
        <vers num="9.5" edition="fp1:solaris"/>
        <vers num="9.5" edition="fp1:linux"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0174" published="2009-01-20" name="CVE-2009-0174" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in the HREF attribute of a REF element in a .asx file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47851" source="XF">vuplayer-asx-bo(47851)</ref>
      <ref url="http://www.securityfocus.com/bid/33185" source="BID">33185</ref>
      <ref url="http://www.milw0rm.com/exploits/7715" source="MILW0RM">7715</ref>
      <ref url="http://www.milw0rm.com/exploits/7714" source="MILW0RM">7714</ref>
      <ref url="http://www.milw0rm.com/exploits/7713" source="MILW0RM">7713</ref>
      <ref url="http://www.milw0rm.com/exploits/7709" source="MILW0RM">7709</ref>
      <ref url="http://securityreason.com/securityalert/4918" source="SREASON">4918</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vuplayer" name="vuplayer">
        <vers num="2.49"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0175" published="2009-01-20" name="CVE-2009-0175" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Heathco Software MP3 TrackMaker 1.5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in an invalid .mp3 file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47852" source="XF">mp3trackmaker-mp3-bo(47852)</ref>
      <ref url="http://www.securityfocus.com/bid/33183" source="BID">33183</ref>
      <ref url="http://www.milw0rm.com/exploits/7708" source="MILW0RM">7708</ref>
      <ref url="http://securityreason.com/securityalert/4920" source="SREASON">4920</ref>
    </refs>
    <vuln_soft>
      <prod vendor="heathcosoft" name="mp3_trackmaker">
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0176" published="2009-01-20" name="CVE-2009-0176" modified="2009-05-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in the PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 allow user-assisted remote attackers to execute arbitrary code via (1) a crafted stream in a .pdf file, related to "symWidths"; or (2) a crafted data stream in a .pdf file, related to "bitmaps."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33224" source="BID">33224</ref>
      <ref url="http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB17119" source="CONFIRM" adv="1">http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB17119</ref>
      <ref url="http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB17118" source="CONFIRM" adv="1">http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB17118</ref>
      <ref url="http://secunia.com/advisories/33534" source="SECUNIA" adv="1">33534</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=765" source="IDEFENSE">20090113 RIM BlackBerry Enterprise Server Attachment Service PDF Distiller 'bitmaps' Heap Overflow Vulnerability</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=764" source="IDEFENSE">20090113 RIM BlackBerry Enterprise Server Attachment Service PDF Distiller 'symWidths' Heap Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="research_in_motion_limited" name="blackberry_enterprise_server">
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.1.6"/>
      </prod>
      <prod vendor="research_in_motion_limited" name="blackberry_professional_software">
        <vers num="4.1.4"/>
      </prod>
      <prod vendor="research_in_motion_limited" name="blackberry_unite">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers prev="1" num="1.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0177" published="2009-01-20" name="CVE-2009-0177" modified="2011-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">vmwarebase.dll, as used in the vmware-authd service (aka vmware-authd.exe), in VMware Workstation 6.5.1 build 126130, 6.5.1 and earlier; VMware Player 2.5.1 build 126130, 2.5.1 and earlier; VMware ACE 2.5.1 and earlier; VMware Server 2.0.x before 2.0.1 build 156745; and VMware Fusion before 2.0.2 build 147997 allows remote attackers to cause a denial of service (daemon crash) via a long (1) USER or (2) PASS command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0005.html" source="CONFIRM" patch="1" adv="1">http://www.vmware.com/security/advisories/VMSA-2009-0005.html</ref>
      <ref url="http://seclists.org/fulldisclosure/2009/Apr/0036.html" source="FULLDISC" patch="1">20090403 VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2009/000054.html" source="MLIST" patch="1">[security-announce] 20090403 VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0944" source="VUPEN" adv="1">ADV-2009-0944</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0024" source="VUPEN" adv="1">ADV-2009-0024</ref>
      <ref url="http://www.securitytracker.com/id?1021512" source="SECTRACK">1021512</ref>
      <ref url="http://www.securityfocus.com/bid/34373" source="BID">34373</ref>
      <ref url="http://secunia.com/advisories/34601" source="SECUNIA" adv="1">34601</ref>
      <ref url="http://secunia.com/advisories/33372" source="SECUNIA" adv="1">33372</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6433" source="OVAL">oval:org.mitre.oval:def:6433</ref>
      <ref url="http://osvdb.org/51180" source="OSVDB">51180</ref>
      <ref url="http://milw0rm.com/exploits/7647" source="MILW0RM">7647</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="ace">
        <vers num="2.5.0"/>
        <vers prev="1" num="2.5.1"/>
      </prod>
      <prod vendor="vmware" name="fusion">
        <vers prev="1" num="2.0.1"/>
      </prod>
      <prod vendor="vmware" name="server">
        <vers num="2.0.0"/>
      </prod>
      <prod vendor="vmware" name="vmware_player">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.05"/>
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.5"/>
        <vers prev="1" num="2.5.1"/>
      </prod>
      <prod vendor="vmware" name="vmware_workstation">
        <vers num="4.5.3"/>
        <vers num="5.0"/>
        <vers num="5.5.0"/>
        <vers num="5.5.1"/>
        <vers num="5.5.2"/>
        <vers num="5.5.3"/>
        <vers num="5.5.4"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.5.7"/>
        <vers num="5.5.8"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.5"/>
        <vers num="6.5"/>
        <vers prev="1" num="6.51"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0178" published="2009-01-20" name="CVE-2009-0178" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48010" source="XF">ibm-hmc-unspecified(48010)</ref>
      <ref url="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=4521" source="CONFIRM">http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=4521</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0158" source="VUPEN">ADV-2009-0158</ref>
      <ref url="http://www.securityfocus.com/bid/33293" source="BID">33293</ref>
      <ref url="http://secunia.com/advisories/33518" source="SECUNIA" adv="1">33518</ref>
      <ref url="http://osvdb.org/51432" source="OSVDB">51432</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="hardware_management_console">
        <vers num="7.3.2.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0179" published="2009-01-20" name="CVE-2009-0179" modified="2009-09-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">libmikmod 3.1.11 through 3.2.0, as used by MikMod and possibly other products, allows user-assisted attackers to cause a denial of service (application crash) by loading an XM file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01312.html" source="FEDORA">FEDORA-2009-9112</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01305.html" source="FEDORA">FEDORA-2009-9095</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=479833" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=479833</ref>
      <ref url="http://www.securityfocus.com/bid/33240" source="BID">33240</ref>
      <ref url="http://secunia.com/advisories/34259" source="SECUNIA">34259</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/01/13/2" source="MLIST">[oss-security] 20090113 CVE Request -- libmikmod</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.html" source="SUSE">SUSE-SR:2009:006</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=476339" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=476339</ref>
    </refs>
    <vuln_soft>
      <prod vendor="igno_saitz" name="libmikmod">
        <vers num="3.1.10-1"/>
        <vers num="3.1.10-2"/>
        <vers num="3.1.10-3"/>
        <vers num="3.1.10-4"/>
        <vers num="3.1.10-5"/>
        <vers num="3.1.11-1"/>
        <vers num="3.1.11-2"/>
        <vers num="3.1.11-3"/>
        <vers num="3.1.11-4"/>
        <vers num="3.1.11-5"/>
        <vers num="3.1.11-6"/>
        <vers num="3.1.12"/>
        <vers num="3.1.9-1"/>
        <vers num="3.1.9-2"/>
        <vers num="3.1.9-3"/>
        <vers num="3.1.9-4"/>
        <vers num="3.1.9-5"/>
        <vers num="3.1.9-6"/>
        <vers num="3.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0180" published="2009-01-20" name="CVE-2009-0180" modified="2009-01-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Certain Fedora build scripts for nfs-utils before 1.1.2-9.fc9 on Fedora 9, and before 1.1.4-6.fc10 on Fedora 10, omit TCP Wrapper support, which might allow remote attackers to bypass intended access restrictions, possibly a related issue to CVE-2008-1376.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00526.html" source="FEDORA">FEDORA-2009-0297</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00376.html" source="FEDORA">FEDORA-2009-0266</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=477864" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=477864</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48058" source="XF">nfsutils-tcpwrapper-security-bypass(48058)</ref>
      <ref url="http://www.securityfocus.com/bid/33294" source="BID">33294</ref>
      <ref url="http://secunia.com/advisories/33545" source="SECUNIA" adv="1">33545</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nfs" name="nfs-utils">
        <vers num="0.2"/>
        <vers num="0.2.1"/>
        <vers num="0.3.1"/>
        <vers num="0.3.3"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.10"/>
        <vers num="1.0.11"/>
        <vers num="1.0.12"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7" edition="pre-1"/>
        <vers num="1.0.7" edition="pre-2"/>
        <vers num="1.0.8" edition="rc-1"/>
        <vers num="1.0.8" edition="rc-2"/>
        <vers num="1.0.8" edition="rc-3"/>
        <vers num="1.0.8" edition="rc-4"/>
        <vers num="1.0.9"/>
        <vers num="1.1.0" edition="rc-1"/>
        <vers num="1.1.1"/>
        <vers prev="1" num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers prev="1" num="1.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0181" published="2009-01-20" name="CVE-2009-0181" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in VUPlayer allows user-assisted attackers to have an unknown impact via a long file, as demonstrated by a file composed entirely of 'A' characters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48169" source="XF">vuplayer-file-bo(48169)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/499810/100/0/threaded" source="BUGTRAQ">20090106 VUPLAYER BufferOver flow POC</ref>
      <ref url="http://securityreason.com/securityalert/4921" source="SREASON">4921</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vuplayer" name="vuplayer">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0182" published="2009-01-20" name="CVE-2009-0182" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in a File line in a .pls file, as demonstrated by an http URL on a File1 line.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48170" source="XF">vuplayer-fileline-bo(48170)</ref>
      <ref url="http://www.milw0rm.com/exploits/7695" source="MILW0RM">7695</ref>
      <ref url="http://securityreason.com/securityalert/4923" source="SREASON">4923</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vuplayer" name="vuplayer">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.01"/>
        <vers num="1.04"/>
        <vers num="1.05"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.4"/>
        <vers num="1.5"/>
        <vers num="1.6"/>
        <vers num="1.7"/>
        <vers num="1.8"/>
        <vers num="1.9"/>
        <vers num="2.0"/>
        <vers num="2.01"/>
        <vers num="2.02"/>
        <vers num="2.03"/>
        <vers num="2.1"/>
        <vers num="2.11"/>
        <vers num="2.2"/>
        <vers num="2.21"/>
        <vers num="2.22"/>
        <vers num="2.23"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.41"/>
        <vers num="2.42"/>
        <vers num="2.43"/>
        <vers num="2.44"/>
        <vers num="2.45"/>
        <vers num="2.46"/>
        <vers num="2.47"/>
        <vers num="2.48"/>
        <vers prev="1" num="2.49"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0183" published="2009-02-03" name="CVE-2009-0183" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Remote Control Server in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allows remote attackers to execute arbitrary code via a long Authorization header in an HTTP request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0302" source="VUPEN">ADV-2009-0302</ref>
      <ref url="http://www.securityfocus.com/bid/33554" source="BID">33554</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500604/100/0/threaded" source="BUGTRAQ">20090202 Secunia Research: Free Download Manager Remote Control Server Buffer Overflow</ref>
      <ref url="http://www.milw0rm.com/exploits/7986" source="MILW0RM">7986</ref>
      <ref url="http://secunia.com/secunia_research/2009-3/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-3/</ref>
      <ref url="http://secunia.com/advisories/33524" source="SECUNIA" adv="1">33524</ref>
      <ref url="http://osvdb.org/51745" source="OSVDB">51745</ref>
    </refs>
    <vuln_soft>
      <prod vendor="free_download_manager" name="free_download_manager">
        <vers num="2.5"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0184" published="2009-02-03" name="CVE-2009-0184" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple buffer overflows in the torrent parsing implementation in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allow remote attackers to execute arbitrary code via (1) a long file name within a torrent file, (2) a long tracker URL in a torrent file, or (3) a long comment in a torrent file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0302" source="VUPEN">ADV-2009-0302</ref>
      <ref url="http://www.securityfocus.com/bid/33555" source="BID">33555</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500605/100/0/threaded" source="BUGTRAQ">20090202 Secunia Research: Free Download Manager Torrent Parsing Buffer Overflows</ref>
      <ref url="http://secunia.com/secunia_research/2009-5/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-5/</ref>
      <ref url="http://secunia.com/advisories/33524" source="SECUNIA" adv="1">33524</ref>
    </refs>
    <vuln_soft>
      <prod vendor="free_download_manager" name="free_download_manager">
        <vers num="2.5"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0185" published="2009-06-02" name="CVE-2009-0185" modified="2009-06-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted MS ADPCM encoded audio data in an AVI movie file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1469" source="VUPEN" patch="1" adv="1">ADV-2009-1469</ref>
      <ref url="http://support.apple.com/kb/HT3591" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3591</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-01-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50894" source="XF">quicktime-msadpcm-bo(50894)</ref>
      <ref url="http://www.securitytracker.com/id?1022314" source="SECTRACK">1022314</ref>
      <ref url="http://www.securityfocus.com/bid/35163" source="BID">35163</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504006/100/0/threaded" source="BUGTRAQ">20090602 Secunia Research: Apple QuickTime MS ADPCM Encoding Buffer Overflow</ref>
      <ref url="http://secunia.com/secunia_research/2009-6/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-6/</ref>
      <ref url="http://secunia.com/advisories/35091" source="SECUNIA" adv="1">35091</ref>
      <ref url="http://osvdb.org/54879" source="OSVDB">54879</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3"/>
        <vers num="4.1.2" edition="-"/>
        <vers num="4.1.2" edition="-:windows"/>
        <vers num="4.1.2" edition="-:mac"/>
        <vers num="5.0"/>
        <vers num="5.0.1" edition="-"/>
        <vers num="5.0.1" edition="-:windows"/>
        <vers num="5.0.1" edition="-:mac"/>
        <vers num="5.0.2" edition="-"/>
        <vers num="5.0.2" edition="-:windows"/>
        <vers num="5.0.2" edition="-:mac"/>
        <vers num="6.0" edition="-"/>
        <vers num="6.0" edition="-:windows"/>
        <vers num="6.0.0" edition="-"/>
        <vers num="6.0.0" edition="-:windows"/>
        <vers num="6.0.0" edition="-:mac"/>
        <vers num="6.0.1" edition="-"/>
        <vers num="6.0.1" edition="-:windows"/>
        <vers num="6.0.1" edition="-:mac"/>
        <vers num="6.0.2" edition="-"/>
        <vers num="6.0.2" edition="-:windows"/>
        <vers num="6.0.2" edition="-:mac"/>
        <vers num="6.1"/>
        <vers num="6.1.0" edition="-"/>
        <vers num="6.1.0" edition="-:mac"/>
        <vers num="6.1.0" edition="-:windows"/>
        <vers num="6.1.1" edition="-"/>
        <vers num="6.1.1" edition="-:windows"/>
        <vers num="6.1.1" edition="-:mac"/>
        <vers num="6.2.0" edition="-"/>
        <vers num="6.2.0" edition="-:windows"/>
        <vers num="6.2.0" edition="-:mac"/>
        <vers num="6.3.0" edition="-"/>
        <vers num="6.3.0" edition="-:mac"/>
        <vers num="6.3.0" edition="-:windows"/>
        <vers num="6.4.0" edition="-"/>
        <vers num="6.4.0" edition="-:mac"/>
        <vers num="6.4.0" edition="-:windows"/>
        <vers num="6.5"/>
        <vers num="6.5.0" edition="-"/>
        <vers num="6.5.0" edition="-:windows"/>
        <vers num="6.5.0" edition="-:mac"/>
        <vers num="6.5.1" edition="-"/>
        <vers num="6.5.1" edition="-:mac"/>
        <vers num="6.5.1" edition="-:windows"/>
        <vers num="6.5.2" edition="-"/>
        <vers num="6.5.2" edition="-:mac"/>
        <vers num="6.5.2" edition="-:windows"/>
        <vers num="7.0" edition=""/>
        <vers num="7.0" edition=":windows"/>
        <vers num="7.0" edition="-"/>
        <vers num="7.0" edition="-:windows"/>
        <vers num="7.0.0" edition="-"/>
        <vers num="7.0.0" edition="-:windows"/>
        <vers num="7.0.0" edition="-:mac"/>
        <vers num="7.0.1" edition=""/>
        <vers num="7.0.1" edition=":windows"/>
        <vers num="7.0.1" edition="-"/>
        <vers num="7.0.1" edition="-:mac"/>
        <vers num="7.0.1" edition="-:windows"/>
        <vers num="7.0.2" edition=""/>
        <vers num="7.0.2" edition=":windows"/>
        <vers num="7.0.2" edition="-"/>
        <vers num="7.0.2" edition="-:windows"/>
        <vers num="7.0.2" edition="-:mac"/>
        <vers num="7.0.3" edition="-"/>
        <vers num="7.0.3" edition="-:windows"/>
        <vers num="7.0.3" edition="-:mac"/>
        <vers num="7.0.4" edition="-"/>
        <vers num="7.0.4" edition="-:windows"/>
        <vers num="7.0.4" edition="-:mac"/>
        <vers num="7.0.8"/>
        <vers num="7.1"/>
        <vers num="7.1.0" edition="-"/>
        <vers num="7.1.0" edition="-:windows"/>
        <vers num="7.1.0" edition="-:mac"/>
        <vers num="7.1.1" edition="-"/>
        <vers num="7.1.1" edition="-:mac"/>
        <vers num="7.1.1" edition="-:windows"/>
        <vers num="7.1.2" edition="-"/>
        <vers num="7.1.2" edition="-:windows"/>
        <vers num="7.1.2" edition="-:mac"/>
        <vers num="7.1.3" edition="-"/>
        <vers num="7.1.3" edition="-:mac"/>
        <vers num="7.1.3" edition="-:windows"/>
        <vers num="7.1.4" edition="-"/>
        <vers num="7.1.4" edition="-:windows"/>
        <vers num="7.1.4" edition="-:mac"/>
        <vers num="7.1.5" edition="-"/>
        <vers num="7.1.5" edition="-:windows"/>
        <vers num="7.1.5" edition="-:mac"/>
        <vers num="7.1.6" edition="-"/>
        <vers num="7.1.6" edition="-:mac"/>
        <vers num="7.1.6" edition="-:windows"/>
        <vers num="7.2" edition=""/>
        <vers num="7.2" edition=":vista"/>
        <vers num="7.2.0" edition="-"/>
        <vers num="7.2.0" edition="-:windows"/>
        <vers num="7.2.0" edition="-:mac"/>
        <vers num="7.2.1" edition="-"/>
        <vers num="7.2.1" edition="-:windows"/>
        <vers num="7.2.1" edition="-:mac"/>
        <vers num="7.3"/>
        <vers num="7.3.0" edition="-"/>
        <vers num="7.3.0" edition="-:windows"/>
        <vers num="7.3.0" edition="-:mac"/>
        <vers num="7.3.1" edition="-"/>
        <vers num="7.3.1" edition="-:windows"/>
        <vers num="7.3.1" edition="-:mac"/>
        <vers num="7.3.1.70"/>
        <vers num="7.4"/>
        <vers num="7.4.0" edition="-"/>
        <vers num="7.4.0" edition="-:mac"/>
        <vers num="7.4.0" edition="-:windows"/>
        <vers num="7.4.1" edition="-"/>
        <vers num="7.4.1" edition="-:mac"/>
        <vers num="7.4.1" edition="-:windows"/>
        <vers num="7.4.4"/>
        <vers num="7.4.5" edition="-"/>
        <vers num="7.4.5" edition="-:windows"/>
        <vers num="7.4.5" edition="-:mac"/>
        <vers num="7.5"/>
        <vers num="7.5.0" edition="-"/>
        <vers num="7.5.0" edition="-:windows"/>
        <vers num="7.5.0" edition="-:mac"/>
        <vers num="7.5.5" edition="-"/>
        <vers num="7.5.5" edition="-:windows"/>
        <vers num="7.5.5" edition="-:mac"/>
        <vers num="7.6.0"/>
        <vers prev="1" num="7.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0186" published="2009-03-04" name="CVE-2009-0186" modified="2010-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in libsndfile 1.0.18, as used in Winamp and other products, allows context-dependent attackers to execute arbitrary code via crafted description chunks in a CAF audio file, leading to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49038" source="XF">libsndfile-caf-bo(49038)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0585" source="VUPEN" adv="1">ADV-2009-0585</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0584" source="VUPEN" adv="1">ADV-2009-0584</ref>
      <ref url="http://www.ubuntu.com/usn/USN-749-1" source="UBUNTU">USN-749-1</ref>
      <ref url="http://www.securitytracker.com/id?1021784" source="SECTRACK">1021784</ref>
      <ref url="http://www.securityfocus.com/bid/33963" source="BID">33963</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501413/100/0/threaded" source="BUGTRAQ">20090303 Secunia Research: libsndfile CAF Processing Integer Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501399/100/0/threaded" source="BUGTRAQ">20090303 Secunia Research: Winamp CAF Processing Integer Overflow Vulnerability</ref>
      <ref url="http://www.mega-nerd.com/libsndfile/NEWS" source="CONFIRM">http://www.mega-nerd.com/libsndfile/NEWS</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1742" source="DEBIAN">DSA-1742</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-16.xml" source="GENTOO">GLSA-200904-16</ref>
      <ref url="http://secunia.com/secunia_research/2009-8/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-8/</ref>
      <ref url="http://secunia.com/secunia_research/2009-7/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-7/</ref>
      <ref url="http://secunia.com/advisories/34791" source="SECUNIA">34791</ref>
      <ref url="http://secunia.com/advisories/34642" source="SECUNIA">34642</ref>
      <ref url="http://secunia.com/advisories/34526" source="SECUNIA">34526</ref>
      <ref url="http://secunia.com/advisories/34316" source="SECUNIA">34316</ref>
      <ref url="http://secunia.com/advisories/33981" source="SECUNIA" adv="1">33981</ref>
      <ref url="http://secunia.com/advisories/33980" source="SECUNIA" adv="1">33980</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.html" source="SUSE">SUSE-SR:2009:008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mega-nerd" name="libsndfile">
        <vers num="0.0.28"/>
        <vers num="0.0.8"/>
        <vers num="1.0.0" edition="rc1"/>
        <vers num="1.0.0" edition="rc6"/>
        <vers num="1.0.1"/>
        <vers num="1.0.10"/>
        <vers num="1.0.11"/>
        <vers num="1.0.12"/>
        <vers num="1.0.13"/>
        <vers num="1.0.14"/>
        <vers num="1.0.15"/>
        <vers num="1.0.16"/>
        <vers num="1.0.17"/>
        <vers prev="1" num="1.0.18"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
      </prod>
      <prod vendor="nullsoft" name="winamp">
        <vers num="5.541"/>
        <vers num="5.55"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0187" published="2009-02-26" name="CVE-2009-0187" modified="2010-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Orbit Downloader 2.8.2 and 2.8.3, and possibly other versions before 2.8.5, allows remote attackers to execute arbitrary code via a crafted HTTP URL with a long host name, which is not properly handled when constructing a "Connecting" log message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0521" source="VUPEN" patch="1" adv="1">ADV-2009-0521</ref>
      <ref url="http://www.securityfocus.com/bid/33894" source="BID" patch="1">33894</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48932" source="XF">orbitdownloader-connecting-bo(48932)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501220/100/0/threaded" source="BUGTRAQ">20090225 Secunia Research: Orbit Downloader Long URL Parsing Buffer Overflow</ref>
      <ref url="http://secunia.com/secunia_research/2009-9/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-9/</ref>
      <ref url="http://secunia.com/advisories/33843" source="SECUNIA" adv="1">33843</ref>
      <ref url="http://osvdb.org/52294" source="OSVDB">52294</ref>
    </refs>
    <vuln_soft>
      <prod vendor="orbitdownloader" name="orbit_downloader">
        <vers num="2.8.2"/>
        <vers num="2.8.3"/>
        <vers num="2.8.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0188" published="2009-06-02" name="CVE-2009-0188" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie composed of a Sorenson 3 video file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1469" source="VUPEN" patch="1" adv="1">ADV-2009-1469</ref>
      <ref url="http://support.apple.com/kb/HT3591" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3591</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-01-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50886" source="XF">quicktime-sorensonvideo-code-execution(50886)</ref>
      <ref url="http://www.securitytracker.com/id?1022314" source="SECTRACK">1022314</ref>
      <ref url="http://www.securityfocus.com/bid/35159" source="BID">35159</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504007/100/0/threaded" source="BUGTRAQ">20090602 Secunia Research: QuickTime Sorenson Video 3 Content Parsing Vulnerability</ref>
      <ref url="http://secunia.com/secunia_research/2009-10/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-10/</ref>
      <ref url="http://secunia.com/advisories/35091" source="SECUNIA" adv="1">35091</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3"/>
        <vers num="4.1.2" edition="-"/>
        <vers num="4.1.2" edition="-:windows"/>
        <vers num="4.1.2" edition="-:mac"/>
        <vers num="5.0"/>
        <vers num="5.0.1" edition="-"/>
        <vers num="5.0.1" edition="-:windows"/>
        <vers num="5.0.1" edition="-:mac"/>
        <vers num="5.0.2" edition="-"/>
        <vers num="5.0.2" edition="-:windows"/>
        <vers num="5.0.2" edition="-:mac"/>
        <vers num="6.0" edition="-"/>
        <vers num="6.0" edition="-:windows"/>
        <vers num="6.0.0" edition="-"/>
        <vers num="6.0.0" edition="-:windows"/>
        <vers num="6.0.0" edition="-:mac"/>
        <vers num="6.0.1" edition="-"/>
        <vers num="6.0.1" edition="-:windows"/>
        <vers num="6.0.1" edition="-:mac"/>
        <vers num="6.0.2" edition="-"/>
        <vers num="6.0.2" edition="-:windows"/>
        <vers num="6.0.2" edition="-:mac"/>
        <vers num="6.1"/>
        <vers num="6.1.0" edition="-"/>
        <vers num="6.1.0" edition="-:mac"/>
        <vers num="6.1.0" edition="-:windows"/>
        <vers num="6.1.1" edition="-"/>
        <vers num="6.1.1" edition="-:windows"/>
        <vers num="6.1.1" edition="-:mac"/>
        <vers num="6.2.0" edition="-"/>
        <vers num="6.2.0" edition="-:windows"/>
        <vers num="6.2.0" edition="-:mac"/>
        <vers num="6.3.0" edition="-"/>
        <vers num="6.3.0" edition="-:mac"/>
        <vers num="6.3.0" edition="-:windows"/>
        <vers num="6.4.0" edition="-"/>
        <vers num="6.4.0" edition="-:mac"/>
        <vers num="6.4.0" edition="-:windows"/>
        <vers num="6.5"/>
        <vers num="6.5.0" edition="-"/>
        <vers num="6.5.0" edition="-:windows"/>
        <vers num="6.5.0" edition="-:mac"/>
        <vers num="6.5.1" edition="-"/>
        <vers num="6.5.1" edition="-:mac"/>
        <vers num="6.5.1" edition="-:windows"/>
        <vers num="6.5.2" edition="-"/>
        <vers num="6.5.2" edition="-:mac"/>
        <vers num="6.5.2" edition="-:windows"/>
        <vers num="7.0" edition=""/>
        <vers num="7.0" edition=":windows"/>
        <vers num="7.0" edition="-"/>
        <vers num="7.0" edition="-:windows"/>
        <vers num="7.0.0" edition="-"/>
        <vers num="7.0.0" edition="-:windows"/>
        <vers num="7.0.0" edition="-:mac"/>
        <vers num="7.0.1" edition=""/>
        <vers num="7.0.1" edition=":windows"/>
        <vers num="7.0.1" edition="-"/>
        <vers num="7.0.1" edition="-:mac"/>
        <vers num="7.0.1" edition="-:windows"/>
        <vers num="7.0.2" edition=""/>
        <vers num="7.0.2" edition=":windows"/>
        <vers num="7.0.2" edition="-"/>
        <vers num="7.0.2" edition="-:windows"/>
        <vers num="7.0.2" edition="-:mac"/>
        <vers num="7.0.3" edition="-"/>
        <vers num="7.0.3" edition="-:windows"/>
        <vers num="7.0.3" edition="-:mac"/>
        <vers num="7.0.4" edition="-"/>
        <vers num="7.0.4" edition="-:windows"/>
        <vers num="7.0.4" edition="-:mac"/>
        <vers num="7.0.8"/>
        <vers num="7.1"/>
        <vers num="7.1.0" edition="-"/>
        <vers num="7.1.0" edition="-:windows"/>
        <vers num="7.1.0" edition="-:mac"/>
        <vers num="7.1.1" edition="-"/>
        <vers num="7.1.1" edition="-:mac"/>
        <vers num="7.1.1" edition="-:windows"/>
        <vers num="7.1.2" edition="-"/>
        <vers num="7.1.2" edition="-:windows"/>
        <vers num="7.1.2" edition="-:mac"/>
        <vers num="7.1.3" edition="-"/>
        <vers num="7.1.3" edition="-:mac"/>
        <vers num="7.1.3" edition="-:windows"/>
        <vers num="7.1.4" edition="-"/>
        <vers num="7.1.4" edition="-:windows"/>
        <vers num="7.1.4" edition="-:mac"/>
        <vers num="7.1.5" edition="-"/>
        <vers num="7.1.5" edition="-:windows"/>
        <vers num="7.1.5" edition="-:mac"/>
        <vers num="7.1.6" edition="-"/>
        <vers num="7.1.6" edition="-:mac"/>
        <vers num="7.1.6" edition="-:windows"/>
        <vers num="7.2" edition=""/>
        <vers num="7.2" edition=":vista"/>
        <vers num="7.2.0" edition="-"/>
        <vers num="7.2.0" edition="-:windows"/>
        <vers num="7.2.0" edition="-:mac"/>
        <vers num="7.2.1" edition="-"/>
        <vers num="7.2.1" edition="-:windows"/>
        <vers num="7.2.1" edition="-:mac"/>
        <vers num="7.3"/>
        <vers num="7.3.0" edition="-"/>
        <vers num="7.3.0" edition="-:windows"/>
        <vers num="7.3.0" edition="-:mac"/>
        <vers num="7.3.1" edition="-"/>
        <vers num="7.3.1" edition="-:windows"/>
        <vers num="7.3.1" edition="-:mac"/>
        <vers num="7.3.1.70"/>
        <vers num="7.4"/>
        <vers num="7.4.0" edition="-"/>
        <vers num="7.4.0" edition="-:mac"/>
        <vers num="7.4.0" edition="-:windows"/>
        <vers num="7.4.1" edition="-"/>
        <vers num="7.4.1" edition="-:mac"/>
        <vers num="7.4.1" edition="-:windows"/>
        <vers num="7.4.4"/>
        <vers num="7.4.5" edition="-"/>
        <vers num="7.4.5" edition="-:windows"/>
        <vers num="7.4.5" edition="-:mac"/>
        <vers num="7.5"/>
        <vers num="7.5.0" edition="-"/>
        <vers num="7.5.0" edition="-:windows"/>
        <vers num="7.5.0" edition="-:mac"/>
        <vers num="7.5.5" edition="-"/>
        <vers num="7.5.5" edition="-:windows"/>
        <vers num="7.5.5" edition="-:mac"/>
        <vers num="7.6.0"/>
        <vers prev="1" num="7.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2009-0189" reject="1" published="2011-02-01" name="CVE-2009-0189" modified="2011-02-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2009-1012.  Reason: This candidate is a reservation duplicate of CVE-2009-1012.  Notes: All CVE users should reference CVE-2009-1012 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" seq="2009-0190" reject="1" published="2011-02-01" name="CVE-2009-0190" modified="2011-02-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2009-1016.  Reason: This candidate is a reservation duplicate of CVE-2009-1016.  Notes: All CVE users should reference CVE-2009-1016 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0191" published="2009-03-10" name="CVE-2009-0191" modified="2009-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 3.0.2009.1301, does not properly handle a JBIG2 symbol dictionary segment with zero new symbols, which allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a dereference of an uninitialized memory location.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0634" source="VUPEN" patch="1" adv="1">ADV-2009-0634</ref>
      <ref url="http://www.foxitsoftware.com/pdf/reader/security.htm#Processing" source="CONFIRM" patch="1" adv="1">http://www.foxitsoftware.com/pdf/reader/security.htm#Processing</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49135" source="XF">foxitreader-jbig2-code-execution(49135)</ref>
      <ref url="http://www.securitytracker.com/id?1021822" source="SECTRACK">1021822</ref>
      <ref url="http://www.securityfocus.com/bid/34035" source="BID">34035</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501590/100/0/threaded" source="BUGTRAQ">20090309 Secunia Research: Foxit Reader JBIG2 Symbol Dictionary Processing Vulnerability</ref>
      <ref url="http://secunia.com/secunia_research/2009-11/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-11/</ref>
      <ref url="http://secunia.com/advisories/34036" source="SECUNIA" adv="1">34036</ref>
    </refs>
    <vuln_soft>
      <prod vendor="foxitsoftware" name="foxit_reader">
        <vers num="2.3"/>
        <vers num="3.0"/>
        <vers num="3.0.2009.1301"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0192" published="2009-07-14" name="CVE-2009-0192" modified="2009-07-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Off-by-one error in the iMonitor component in Novell eDirectory 8.8 SP3, 8.8 SP3 FTF3, and possibly other versions allows remote attackers to execute arbitrary code via an HTTP request with a crafted Accept-Language header, which triggers a stack-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/51703" source="XF">edirectory-imonitor-acceptlanguage-bo(51703)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1883" source="VUPEN" adv="1">ADV-2009-1883</ref>
      <ref url="http://www.securityfocus.com/bid/35666" source="BID">35666</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504924/100/0/threaded" source="BUGTRAQ">20090714 Secunia Research: Novell eDirectory iMonitor "Accept-Language" Buffer Overflow</ref>
      <ref url="http://www.novell.com/support/viewContent.do?externalId=3426981" source="CONFIRM">http://www.novell.com/support/viewContent.do?externalId=3426981</ref>
      <ref url="http://secunia.com/secunia_research/2009-13/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-13/</ref>
      <ref url="http://secunia.com/advisories/34160" source="SECUNIA" adv="1">34160</ref>
      <ref url="http://osvdb.org/55847" source="OSVDB">55847</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="edirectory">
        <vers num="8.8" edition="sp3"/>
        <vers num="8.8" edition="sp3:ftf3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0193" published="2009-03-24" name="CVE-2009-0193" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Adobe Acrobat Reader 9 before 9.1, 8 before 8.1.4, and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a PDF file with a malformed JBIG2 symbol dictionary segment, a different vulnerability than CVE-2009-1061 and CVE-2009-1062.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34229" source="BID" patch="1">34229</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-04.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-04.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1019" source="VUPEN" adv="1">ADV-2009-1019</ref>
      <ref url="http://www.securitytracker.com/id?1021892" source="SECTRACK">1021892</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502155/100/0/threaded" source="BUGTRAQ">20090325 Secunia Research: Adobe Reader JBIG2 Symbol Dictionary Buffer Overflow</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0376.html" source="REDHAT">RHSA-2009:0376</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-256788-1" source="SUNALERT">256788</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-17.xml" source="GENTOO">GLSA-200904-17</ref>
      <ref url="http://secunia.com/secunia_research/2009-14/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-14/</ref>
      <ref url="http://secunia.com/advisories/34790" source="SECUNIA" adv="1">34790</ref>
      <ref url="http://secunia.com/advisories/34706" source="SECUNIA" adv="1">34706</ref>
      <ref url="http://secunia.com/advisories/34490" source="SECUNIA" adv="1">34490</ref>
      <ref url="http://secunia.com/advisories/34392" source="SECUNIA" adv="1">34392</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html" source="SUSE">SUSE-SR:2009:009</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00005.html" source="SUSE">SUSE-SA:2009:014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.5"/>
        <vers num="7.0.7"/>
        <vers num="7.0.8"/>
        <vers num="7.0.9"/>
        <vers prev="1" num="7.1.0"/>
        <vers num="8.0"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers prev="1" num="8.1.2"/>
        <vers prev="1" num="9.0"/>
      </prod>
      <prod vendor="adobe" name="reader">
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.5"/>
        <vers num="7.0.7"/>
        <vers num="7.0.8"/>
        <vers num="7.0.9"/>
        <vers prev="1" num="7.1.0"/>
        <vers num="8.1.1"/>
        <vers prev="1" num="8.1.2"/>
        <vers prev="1" num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0194" published="2009-05-11" name="CVE-2009-0194" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The domain-locking implementation in the GARMINAXCONTROL.GarminAxControl_t.1 ActiveX control in npGarmin.dll in the Garmin Communicator Plug-In 2.6.4.0 does not properly enforce the restrictions that (1) download and (2) upload requests come from a web site specified by the user, which allows remote attackers to obtain sensitive information or reconfigure Garmin GPS devices via unspecified vectors related to a "synchronisation error."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50360" source="XF">communicator-domain-security-bypass(50360)</ref>
      <ref url="http://www.securityfocus.com/bid/34858" source="BID">34858</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503319/100/0/threaded" source="BUGTRAQ">20090507 Secunia Research: Garmin Communicator Plug-In Domain Locking Security Bypass</ref>
      <ref url="http://securitytracker.com/id?1022173" source="SECTRACK">1022173</ref>
      <ref url="http://secunia.com/secunia_research/2009-16/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-16/</ref>
      <ref url="http://secunia.com/advisories/34326" source="SECUNIA" adv="1">34326</ref>
      <ref url="http://osvdb.org/54258" source="OSVDB">54258</ref>
    </refs>
    <vuln_soft>
      <prod vendor="garmin" name="garmin_communicator_plugin">
        <vers num="2.6.4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0195" published="2009-04-23" name="CVE-2009-0195" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, allows remote attackers to execute arbitrary code via a PDF file with crafted JBIG2 symbol dictionary segments.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1040" source="VUPEN">ADV-2010-1040</ref>
      <ref url="http://www.securityfocus.com/bid/34791" source="BID">34791</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502762/100/0/threaded" source="BUGTRAQ">20090417 Secunia Research: Xpdf JBIG2 Symbol Dictionary Buffer Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502759/100/0/threaded" source="BUGTRAQ">20090417 Secunia Research: CUPS pdftops JBIG2 Symbol Dictionary Buffer Overflow</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0480.html" source="REDHAT">RHSA-2009:0480</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:087" source="MANDRIVA">MDVSA-2010:087</ref>
      <ref url="http://secunia.com/secunia_research/2009-18/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-18/</ref>
      <ref url="http://secunia.com/secunia_research/2009-17/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-17/</ref>
      <ref url="http://secunia.com/advisories/35064" source="SECUNIA">35064</ref>
      <ref url="http://secunia.com/advisories/34963" source="SECUNIA">34963</ref>
      <ref url="http://secunia.com/advisories/34756" source="SECUNIA">34756</ref>
      <ref url="http://secunia.com/advisories/34481" source="SECUNIA">34481</ref>
      <ref url="http://secunia.com/advisories/34291" source="SECUNIA">34291</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0458.html" source="REDHAT">RHSA-2009:0458</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10076" source="OVAL">oval:org.mitre.oval:def:10076</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.3.9"/>
      </prod>
      <prod vendor="foolabs" name="xpdf">
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.5a"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7a"/>
        <vers num="0.80"/>
        <vers num="0.90"/>
        <vers num="0.91"/>
        <vers num="0.91a"/>
        <vers num="0.91b"/>
        <vers num="0.91c"/>
        <vers num="0.92"/>
        <vers num="0.92a"/>
        <vers num="0.92b"/>
        <vers num="0.92c"/>
        <vers num="0.92d"/>
        <vers num="0.92e"/>
        <vers num="0.93"/>
        <vers num="0.93a"/>
        <vers num="0.93b"/>
        <vers num="0.93c"/>
        <vers num="1.00"/>
        <vers num="1.00a"/>
        <vers num="1.01"/>
        <vers num="2.00"/>
        <vers num="2.01"/>
        <vers num="2.02"/>
        <vers num="2.03"/>
        <vers num="3.0.1"/>
        <vers num="3.00"/>
        <vers prev="1" num="3.02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0196" published="2009-04-16" name="CVE-2009-0196" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and probably earlier versions, allows remote attackers to execute arbitrary code via a PDF file with a JBIG2 symbol dictionary segment with a large run length value.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34445" source="BID" patch="1">34445</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00461.html" source="FEDORA">FEDORA-2009-3710</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00460.html" source="FEDORA">FEDORA-2009-3709</ref>
      <ref url="https://bugzilla.redhat.com/attachment.cgi?id=337747" source="MISC">https://bugzilla.redhat.com/attachment.cgi?id=337747</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1708" source="VUPEN">ADV-2009-1708</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0983" source="VUPEN" adv="1">ADV-2009-0983</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-757-1" source="UBUNTU">USN-757-1</ref>
      <ref url="http://www.securitytracker.com/id?1022029" source="SECTRACK">1022029</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502757/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0060-1 ghostscript</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502586/100/0/threaded" source="BUGTRAQ">20090409 Secunia Research: Ghostscript jbig2dec JBIG2 Processing Buffer Overflow</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0421.html" source="REDHAT">RHSA-2009:0421</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:095" source="MANDRIVA">MDVSA-2009:095</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0060" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0060</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-262288-1" source="SUNALERT">262288</ref>
      <ref url="http://secunia.com/secunia_research/2009-21/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-21/</ref>
      <ref url="http://secunia.com/advisories/35569" source="SECUNIA">35569</ref>
      <ref url="http://secunia.com/advisories/35559" source="SECUNIA">35559</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA">35416</ref>
      <ref url="http://secunia.com/advisories/34732" source="SECUNIA">34732</ref>
      <ref url="http://secunia.com/advisories/34729" source="SECUNIA">34729</ref>
      <ref url="http://secunia.com/advisories/34667" source="SECUNIA">34667</ref>
      <ref url="http://secunia.com/advisories/34292" source="SECUNIA" adv="1">34292</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10533" source="OVAL">oval:org.mitre.oval:def:10533</ref>
      <ref url="http://osvdb.org/53492" source="OSVDB">53492</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html" source="SUSE">SUSE-SR:2009:009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ghostscript" name="ghostscript">
        <vers num="0"/>
        <vers num="5.50"/>
        <vers num="7.07"/>
        <vers num="8.0.1"/>
        <vers num="8.15"/>
        <vers num="8.15.2"/>
        <vers num="8.54"/>
        <vers num="8.56"/>
        <vers num="8.57"/>
        <vers num="8.60"/>
        <vers num="8.61"/>
        <vers num="8.62"/>
        <vers num="8.63"/>
        <vers prev="1" num="8.64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0197" published="2009-04-09" name="CVE-2009-0197" modified="2009-04-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in the FORMATS Plugin before 4.23 for IrfanView allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large XPM file that triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49717" source="XF" patch="1">irfanview-formatsplugin-xpm-bo(49717)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0953" source="VUPEN" patch="1" adv="1">ADV-2009-0953</ref>
      <ref url="http://www.irfanview.com/plugins.htm" source="CONFIRM" patch="1">http://www.irfanview.com/plugins.htm</ref>
      <ref url="http://www.securityfocus.com/bid/34402" source="BID">34402</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502516/100/0/threaded" source="BUGTRAQ">20090407 Secunia Research: IrfanView Formats Plug-in XPM Parsing Integer Overflow</ref>
      <ref url="http://www.osvdb.org/53323" source="OSVDB">53323</ref>
      <ref url="http://secunia.com/secunia_research/2009-20/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-20/</ref>
      <ref url="http://secunia.com/advisories/34525" source="SECUNIA" adv="1">34525</ref>
    </refs>
    <vuln_soft>
      <prod vendor="irfanview" name="formats">
        <vers num="4.00"/>
        <vers num="4.10"/>
        <vers num="4.20"/>
        <vers prev="1" num="4.22"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0198" published="2009-06-11" name="CVE-2009-0198" modified="2010-05-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PDF file that contains JBIG2 text region segments with Huffman encoding.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-161A.html" source="CERT">TA09-161A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1547" source="VUPEN" patch="1" adv="1">ADV-2009-1547</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-07.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-07.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/51015" source="XF">reader-acrobat-jbig2-code-exec(51015)</ref>
      <ref url="http://www.securityfocus.com/bid/35302" source="BID">35302</ref>
      <ref url="http://www.securityfocus.com/bid/35274" source="BID">35274</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504217/100/0/threaded" source="BUGTRAQ">20090610 Secunia Research: Adobe Reader JBIG2 Text Region Segment Buffer Overflow</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1109.html" source="REDHAT">RHSA-2009:1109</ref>
      <ref url="http://securitytracker.com/id?1022361" source="SECTRACK">1022361</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-06.xml" source="GENTOO">GLSA-200907-06</ref>
      <ref url="http://secunia.com/secunia_research/2009-24/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-24/</ref>
      <ref url="http://secunia.com/advisories/35734" source="SECUNIA">35734</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://secunia.com/advisories/35655" source="SECUNIA">35655</ref>
      <ref url="http://secunia.com/advisories/35496" source="SECUNIA">35496</ref>
      <ref url="http://secunia.com/advisories/34580" source="SECUNIA" adv="1">34580</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00000.html" source="SUSE">SUSE-SA:2009:035</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="7.0" edition=""/>
        <vers num="7.0" edition=":standard"/>
        <vers num="7.0" edition=":professional"/>
        <vers num="7.0.1" edition=""/>
        <vers num="7.0.1" edition=":professional"/>
        <vers num="7.0.1" edition=":standard"/>
        <vers num="7.0.2" edition=""/>
        <vers num="7.0.2" edition=":professional"/>
        <vers num="7.0.2" edition=":standard"/>
        <vers num="7.0.3" edition=""/>
        <vers num="7.0.3" edition=":professional"/>
        <vers num="7.0.3" edition=":standard"/>
        <vers num="7.0.4" edition=""/>
        <vers num="7.0.4" edition=":professional"/>
        <vers num="7.0.4" edition=":standard"/>
        <vers num="7.0.5" edition=""/>
        <vers num="7.0.5" edition=":professional"/>
        <vers num="7.0.5" edition=":standard"/>
        <vers num="7.0.6" edition=""/>
        <vers num="7.0.6" edition=":professional"/>
        <vers num="7.0.6" edition=":standard"/>
        <vers num="7.0.7" edition=""/>
        <vers num="7.0.7" edition=":professional"/>
        <vers num="7.0.7" edition=":standard"/>
        <vers num="7.0.8" edition=""/>
        <vers num="7.0.8" edition=":elements"/>
        <vers num="7.0.8" edition=":standard"/>
        <vers num="7.0.8" edition=":professional"/>
        <vers num="7.0.9" edition=""/>
        <vers num="7.0.9" edition=":professional"/>
        <vers num="7.1" edition=""/>
        <vers num="7.1" edition=":standard"/>
        <vers num="7.1" edition=":professional"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1" edition=""/>
        <vers num="7.1.1" edition=":standard"/>
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":professional"/>
        <vers num="8.0" edition=":standard"/>
        <vers num="8.1" edition=""/>
        <vers num="8.1" edition=":standard"/>
        <vers num="8.1.1" edition=""/>
        <vers num="8.1.1" edition=":standard"/>
        <vers num="8.1.1" edition=":professional"/>
        <vers num="8.1.2" edition=""/>
        <vers num="8.1.2" edition=":standard"/>
        <vers num="8.1.2" edition=":professional"/>
        <vers num="8.1.2" edition="security_update"/>
        <vers num="8.1.2" edition="security_update:professional"/>
        <vers num="8.1.3" edition=""/>
        <vers num="8.1.3" edition=":standard"/>
        <vers num="8.1.3" edition=":professional"/>
        <vers num="8.1.4" edition=""/>
        <vers num="8.1.4" edition=":standard"/>
        <vers num="8.1.4" edition=":professional"/>
        <vers num="9"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":standard"/>
        <vers num="9.0.0"/>
        <vers num="9.1" edition=""/>
        <vers num="9.1" edition=":standard"/>
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.0.5"/>
        <vers num="7.0.6"/>
        <vers num="7.0.7"/>
        <vers num="7.0.8"/>
        <vers num="7.0.9"/>
        <vers num="7.1"/>
        <vers num="7.1.1"/>
        <vers num="8.0"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.1.2" edition="security_update"/>
        <vers num="8.1.3"/>
        <vers num="8.1.4"/>
        <vers num="8.1.5"/>
        <vers num="9"/>
        <vers num="9.1"/>
        <vers num="9.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0199" published="2009-09-08" name="CVE-2009-0199" modified="2009-09-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, and VMware ACE 2.5.x before 2.5.3 build 185404 on Windows might allow remote attackers to execute arbitrary code via a video file with crafted dimensions (aka framebuffer parameters).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/2553" source="VUPEN" patch="1" adv="1">ADV-2009-2553</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0012.html" source="CONFIRM" patch="1" adv="1">http://www.vmware.com/security/advisories/VMSA-2009-0012.html</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2009/000065.html" source="MLIST" patch="1">[security-announce] 20090904 VMSA-2009-0012 VMware Movie Decoder, VMware Workstation, VMware Player, and VMware ACE resolve security issues.</ref>
      <ref url="http://www.securityfocus.com/bid/36290" source="BID">36290</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/506286/100/0/threaded" source="BUGTRAQ">20090905 VMSA-2009-0012 VMware Movie Decoder, VMware Workstation, VMware Player, and VMware ACE resolve security issues.</ref>
      <ref url="http://secunia.com/secunia_research/2009-25/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-25/</ref>
      <ref url="http://secunia.com/advisories/34938" source="SECUNIA" adv="1">34938</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="ace">
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
      </prod>
      <prod vendor="vmware" name="movie_decoder">
        <vers num="6.5.3"/>
      </prod>
      <prod vendor="vmware" name="player">
        <vers num="2.5"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.2_build_156735"/>
      </prod>
      <prod vendor="vmware" name="workstation">
        <vers num="6.5"/>
        <vers num="6.5.0"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0200" published="2009-09-02" name="CVE-2009-0200" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer underflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via crafted records in the document table of a Word document, leading to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/2490" source="VUPEN" adv="1">ADV-2009-2490</ref>
      <ref url="http://www.securityfocus.com/bid/36200" source="BID">36200</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/506194/100/0/threaded" source="BUGTRAQ">20090901 Secunia Research: OpenOffice.org Word Document Table Parsing Integer Underflow</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:105" source="MANDRIVA">MDVSA-2010:105</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:091" source="MANDRIVA">MDVSA-2010:091</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:035" source="MANDRIVA">MDVSA-2010:035</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1880" source="DEBIAN">DSA-1880</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020715.1-1" source="SUNALERT">1020715</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-263508-1" source="SUNALERT">263508</ref>
      <ref url="http://secunia.com/secunia_research/2009-26/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-26/</ref>
      <ref url="http://secunia.com/advisories/36750" source="SECUNIA">36750</ref>
      <ref url="http://secunia.com/advisories/35036" source="SECUNIA" adv="1">35036</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10881" source="OVAL">oval:org.mitre.oval:def:10881</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html" source="SUSE">SUSE-SR:2009:015</ref>
      <ref url="http://development.openoffice.org/releases/3.1.1.html" source="MISC">http://development.openoffice.org/releases/3.1.1.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openoffice" name="openoffice.org">
        <vers num="1.0-ru"/>
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3.1"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1" edition="beta2"/>
        <vers num="1.1" edition="rc1"/>
        <vers num="1.1" edition="rc3"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.9.100"/>
        <vers num="1.9.104"/>
        <vers num="1.9.113"/>
        <vers num="1.9.118"/>
        <vers num="1.9.122"/>
        <vers num="1.9.130"/>
        <vers num="1.9.156"/>
        <vers num="1.9.680"/>
        <vers num="1.9.84"/>
        <vers num="1.9.87"/>
        <vers num="1.9.91"/>
        <vers num="1.9.93"/>
        <vers num="1.9.95"/>
        <vers num="2.0" edition="beta2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2" edition="rc1"/>
        <vers num="2.0.2" edition="rc2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.1"/>
        <vers num="2.1.152"/>
        <vers num="2.1.154"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.3"/>
        <vers num="2.3.1"/>
        <vers num="2.4"/>
        <vers num="2.4.1" edition=""/>
        <vers num="2.4.1" edition=":64-bit"/>
        <vers num="3.01"/>
        <vers prev="1" num="3.1"/>
        <vers num="605b"/>
        <vers num="609"/>
        <vers num="614"/>
        <vers num="619"/>
        <vers num="627"/>
        <vers num="633"/>
        <vers num="638"/>
        <vers num="638c"/>
        <vers num="641b"/>
        <vers num="641d"/>
        <vers num="643"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0201" published="2009-09-02" name="CVE-2009-0201" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via unspecified records in a crafted Word document, related to "table parsing."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/2490" source="VUPEN" adv="1">ADV-2009-2490</ref>
      <ref url="http://www.securitytracker.com/id?1022798" source="SECTRACK">1022798</ref>
      <ref url="http://www.securityfocus.com/bid/36200" source="BID">36200</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/506195/100/0/threaded" source="BUGTRAQ">20090901 Secunia Research: OpenOffice.org Word Document Table Parsing Buffer Overflow</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:105" source="MANDRIVA">MDVSA-2010:105</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:091" source="MANDRIVA">MDVSA-2010:091</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:035" source="MANDRIVA">MDVSA-2010:035</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1880" source="DEBIAN">DSA-1880</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020715.1-1" source="SUNALERT">1020715</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-263508-1" source="SUNALERT">263508</ref>
      <ref url="http://secunia.com/secunia_research/2009-27/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-27/</ref>
      <ref url="http://secunia.com/advisories/36750" source="SECUNIA">36750</ref>
      <ref url="http://secunia.com/advisories/35036" source="SECUNIA" adv="1">35036</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10726" source="OVAL">oval:org.mitre.oval:def:10726</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html" source="SUSE">SUSE-SR:2009:015</ref>
      <ref url="http://development.openoffice.org/releases/3.1.1.html" source="MISC">http://development.openoffice.org/releases/3.1.1.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openoffice" name="openoffice.org">
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="2.0"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.3"/>
        <vers num="2.3.1"/>
        <vers num="2.4"/>
        <vers num="2.4.1" edition=""/>
        <vers num="2.4.1" edition=":64-bit"/>
        <vers prev="1" num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0202" published="2009-06-11" name="CVE-2009-0202" modified="2009-06-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Array index error in FL21WIN.DLL in the PowerPoint Freelance Windows 2.1 Translator in Microsoft PowerPoint 2000 and 2002 allows remote attackers to execute arbitrary code via a Freelance file with unspecified "layout information" that triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/51034" source="XF" patch="1">ms-powerpoint-freelance-bo(51034)</ref>
      <ref url="http://www.securityfocus.com/bid/35275" source="BID">35275</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504215/100/0/threaded" source="BUGTRAQ">20090610 Secunia Research: Microsoft PowerPoint Freelance Layout Parsing Vulnerability</ref>
      <ref url="http://www.osvdb.org/54961" source="OSVDB">54961</ref>
      <ref url="http://securitytracker.com/id?1022369" source="SECTRACK">1022369</ref>
      <ref url="http://secunia.com/secunia_research/2009-29/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-29/</ref>
      <ref url="http://secunia.com/advisories/35184" source="SECUNIA" adv="1">35184</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_powerpoint">
        <vers num="2000"/>
        <vers num="2002"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0204" published="2009-01-30" name="CVE-2009-0204" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in HP Select Access 6.1 and 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=123324765514459&amp;w=2" source="HP" patch="1">HPSBMA02403</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48334" source="XF">selectaccess-unspecified-xss(48334)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0296" source="VUPEN">ADV-2009-0296</ref>
      <ref url="http://www.securityfocus.com/bid/33505" source="BID">33505</ref>
      <ref url="http://securitytracker.com/id?1021641" source="SECTRACK">1021641</ref>
      <ref url="http://secunia.com/advisories/33713" source="SECUNIA" adv="1">33713</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=123324765514459&amp;w=2" source="HP">HPSBMA02403</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="select_access">
        <vers num="6.1"/>
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0206" published="2009-02-08" name="CVE-2009-0206" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in NFS in HP ONCplus B.11.31.05 and earlier for HP-UX B.11.31 allows local users to cause a denial of service via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=123394068325944&amp;w=2" source="HP" patch="1" adv="1">SSRT080182</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48556" source="XF">hpux-nfs-dos(48556)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0350" source="VUPEN">ADV-2009-0350</ref>
      <ref url="http://www.securityfocus.com/bid/33653" source="BID">33653</ref>
      <ref url="http://secunia.com/advisories/33860" source="SECUNIA" adv="1">33860</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="oncplus">
        <vers num="b.11.31_01"/>
        <vers num="b.11.31_02"/>
        <vers num="b.11.31_03"/>
        <vers num="b.11.31_04"/>
        <vers prev="1" num="b.11.31_05"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0207" published="2009-03-24" name="CVE-2009-0207" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP-UX B.11.11 running VERITAS Oracle Disk Manager (VRTSodm) 3.5, B.11.23 running VRTSodm 4.1 or VERITAS File System (VRTSvxfs) 4.1, B.11.23 running VRTSodm 5.0 or VRTSvxfs 5.0, and B.11.31 running VRTSodm 5.0 allows local users to gain root privileges via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34226" source="BID" patch="1">34226</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=123792744311063&amp;w=2" source="HP" patch="1">SSRT080171</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=123792744311063&amp;w=2" source="HP" patch="1">SSRT080171</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49403" source="XF">hpux-veritas-unspecified-priv-escalation(49403)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0823" source="VUPEN">ADV-2009-0823</ref>
      <ref url="http://www.securitytracker.com/id?1021891" source="SECTRACK">1021891</ref>
      <ref url="http://secunia.com/advisories/34419" source="SECUNIA">34419</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6352" source="OVAL">oval:org.mitre.oval:def:6352</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="b.11.11"/>
        <vers num="b.11.23"/>
        <vers num="b.11.31"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0208" published="2009-02-26" name="CVE-2009-0208" modified="2009-02-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP Virtual Rooms Client before 7.0.1, when running on Windows, allows remote attackers to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=123567121722181&amp;w=2" source="HP">HPSBGN02410</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=123567121722181&amp;w=2" source="HP">HPSBGN02410</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="virtual_rooms">
        <vers num="6.0"/>
        <vers prev="1" num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0209" published="2009-10-01" name="CVE-2009-0209" modified="2009-10-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">PI Server in OSIsoft PI System before 3.4.380.x does not properly use encryption in the default authentication process, which allows remote attackers to read or modify information in databases via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/506826/100/0/threaded" source="BUGTRAQ">20090930 C4 SCADA Security Advisory - OSISoft PI Server Authentication Weakness</ref>
    </refs>
    <vuln_soft>
      <prod vendor="osisoft" name="pi_server">
        <vers num="2.4"/>
        <vers num="2.6"/>
        <vers num="3.4.363.97"/>
        <vers num="3.4.370"/>
        <vers prev="1" num="3.4.375.99" edition="sp2"/>
        <vers prev="1" num="3.4.375.99" edition="sp2:32bit_windows"/>
        <vers prev="1" num="3.4.375.99" edition="sp2:64bit_windows"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0210" published="2009-02-08" name="CVE-2009-0210" modified="2009-02-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the MLF application in AREVA e-terrahabitat 5.7 and earlier allows remote attackers to execute arbitrary commands or cause a denial of service (system crash) via unspecified vectors, aka PD28578.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per http://www.kb.cert.org/vuls/id/337569 

"III. Solution 

Apply Patch Users of e-terrahabitat version 5.5, 5.6, and 5.7 should apply the e-terrahabitat_560_P20081030_SEC patch immediately."</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/337569" source="CERT-VN">VU#337569</ref>
      <ref url="http://www.securityfocus.com/bid/33637" source="BID">33637</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500689/100/0/threaded" source="BUGTRAQ">20090205 C4 SCADA Security Advisory - AREVA e-terrahabitat / e-terraplatform Multiple Vulnerabilities</ref>
      <ref url="http://www.scada-security.com/vulnerabilities/areva1.html" source="MISC">http://www.scada-security.com/vulnerabilities/areva1.html</ref>
      <ref url="http://secunia.com/advisories/33837" source="SECUNIA">33837</ref>
    </refs>
    <vuln_soft>
      <prod vendor="areva" name="e-terrahabitat">
        <vers num="5.5"/>
        <vers num="5.6"/>
        <vers prev="1" num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0211" published="2009-02-08" name="CVE-2009-0211" modified="2009-02-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the WebFGServer application in AREVA e-terrahabitat 5.7 and earlier allows remote attackers to cause a denial of service (system crash) via unknown vectors, aka PD32018.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/337569" source="CERT-VN">VU#337569</ref>
      <ref url="http://www.securityfocus.com/bid/33637" source="BID">33637</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500689/100/0/threaded" source="BUGTRAQ">20090205 C4 SCADA Security Advisory - AREVA e-terrahabitat / e-terraplatform Multiple Vulnerabilities</ref>
      <ref url="http://www.scada-security.com/vulnerabilities/areva1.html" source="MISC">http://www.scada-security.com/vulnerabilities/areva1.html</ref>
      <ref url="http://secunia.com/advisories/33837" source="SECUNIA">33837</ref>
    </refs>
    <vuln_soft>
      <prod vendor="areva" name="e-terrahabitat">
        <vers num="5.5"/>
        <vers num="5.6"/>
        <vers prev="1" num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0212" published="2009-02-08" name="CVE-2009-0212" modified="2009-02-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the WebFGServer application in AREVA e-terrahabitat 5.7 and earlier allows remote attackers to cause a denial of service (system crash) via unknown vectors, aka PD32020.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per http://www.kb.cert.org/vuls/id/337569 

"III. Solution

 Apply Patch Users of e-terrahabitat version 5.5, 5.6, and 5.7 should apply the e-terrahabitat_560_P20081030_SEC patch immediately."</sol>
    </sols>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/337569" source="CERT-VN">VU#337569</ref>
      <ref url="http://www.securityfocus.com/bid/33637" source="BID">33637</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500689/100/0/threaded" source="BUGTRAQ">20090205 C4 SCADA Security Advisory - AREVA e-terrahabitat / e-terraplatform Multiple Vulnerabilities</ref>
      <ref url="http://www.scada-security.com/vulnerabilities/areva1.html" source="MISC">http://www.scada-security.com/vulnerabilities/areva1.html</ref>
      <ref url="http://secunia.com/advisories/33837" source="SECUNIA">33837</ref>
    </refs>
    <vuln_soft>
      <prod vendor="areva" name="e-terrahabitat">
        <vers num="5.5"/>
        <vers num="5.6"/>
        <vers prev="1" num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0213" published="2009-02-08" name="CVE-2009-0213" modified="2009-02-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the NETIO application in AREVA e-terrahabitat 5.7 and earlier allows remote attackers to cause a denial of service (system crash) via unknown vectors, aka PD32021.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per http://www.kb.cert.org/vuls/id/337569


"III. Solution
Apply Patch


Users of e-terrahabitat version 5.5, 5.6, and 5.7 should apply the e-terrahabitat_560_P20081030_SEC patch immediately."</sol>
    </sols>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/337569" source="CERT-VN">VU#337569</ref>
      <ref url="http://www.securityfocus.com/bid/33637" source="BID">33637</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500689/100/0/threaded" source="BUGTRAQ">20090205 C4 SCADA Security Advisory - AREVA e-terrahabitat / e-terraplatform Multiple Vulnerabilities</ref>
      <ref url="http://www.scada-security.com/vulnerabilities/areva1.html" source="MISC">http://www.scada-security.com/vulnerabilities/areva1.html</ref>
      <ref url="http://secunia.com/advisories/33837" source="SECUNIA">33837</ref>
    </refs>
    <vuln_soft>
      <prod vendor="areva" name="e-terrahabitat">
        <vers num="5.5"/>
        <vers num="5.6"/>
        <vers prev="1" num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0214" published="2009-02-08" name="CVE-2009-0214" modified="2009-02-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the WebFGServer application in AREVA e-terrahabitat 5.7 and earlier allows remote authenticated users to gain privileges via unknown vectors, aka PD32022.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per http://www.kb.cert.org/vuls/id/337569 

"III. Solution 

Apply Patch Users of e-terrahabitat version 5.5, 5.6, and 5.7 should apply the e-terrahabitat_560_P20081030_SEC patch immediately."</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/337569" source="CERT-VN">VU#337569</ref>
      <ref url="http://www.securityfocus.com/bid/33637" source="BID">33637</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500689/100/0/threaded" source="BUGTRAQ">20090205 C4 SCADA Security Advisory - AREVA e-terrahabitat / e-terraplatform Multiple Vulnerabilities</ref>
      <ref url="http://www.scada-security.com/vulnerabilities/areva1.html" source="MISC">http://www.scada-security.com/vulnerabilities/areva1.html</ref>
      <ref url="http://secunia.com/advisories/33837" source="SECUNIA">33837</ref>
    </refs>
    <vuln_soft>
      <prod vendor="areva" name="e-terrahabitat">
        <vers num="5.5"/>
        <vers num="5.6"/>
        <vers prev="1" num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0215" published="2009-03-25" name="CVE-2009-0215" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the GetXMLValue method in the IBM Access Support ActiveX control in IbmEgath.dll, as distributed on IBM and Lenovo computers, allows remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/340420" source="CERT-VN" adv="1">VU#340420</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49409" source="XF">ibm-access-activex-bo(49409)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0824" source="VUPEN" adv="1">ADV-2009-0824</ref>
      <ref url="http://www.securityfocus.com/bid/34228" source="BID">34228</ref>
      <ref url="http://secunia.com/advisories/34470" source="SECUNIA">34470</ref>
      <ref url="http://osvdb.org/52958" source="OSVDB">52958</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="access_support_activex_control">
        <vers num="3.20.284.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0216" published="2009-02-13" name="CVE-2009-0216" modified="2009-02-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">GE Fanuc iFIX 5.0 and earlier relies on client-side authentication involving a weakly encrypted local password file, which allows remote attackers to bypass intended access restrictions and start privileged server login sessions by recovering a password or by using a modified program module.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/310355" source="CERT-VN">VU#310355</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48691" source="XF">gefanucifix-multiple-unauth-access(48691)</ref>
      <ref url="http://www.securityfocus.com/bid/33739" source="BID">33739</ref>
      <ref url="http://www.mcgrewsecurity.com/2009/02/10/ge-fanuc-releases-info-on-ifix-vulnerabilities-vu-310355/" source="MISC">http://www.mcgrewsecurity.com/2009/02/10/ge-fanuc-releases-info-on-ifix-vulnerabilities-vu-310355/</ref>
      <ref url="http://support.gefanuc.com/support/index?page=kbchannel&amp;id=S:KB13253&amp;actp=search" source="CONFIRM" adv="1">http://support.gefanuc.com/support/index?page=kbchannel&amp;id=S:KB13253&amp;actp=search</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ge_fanuc" name="ifix">
        <vers num="2.0"/>
        <vers num="2.2"/>
        <vers num="2.21"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="3.0"/>
        <vers num="3.5"/>
        <vers num="4.0"/>
        <vers num="4.5"/>
        <vers prev="1" num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0217" published="2009-07-14" name="CVE-2009-0217" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-294A.html" source="CERT">TA09-294A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/466161" source="CERT-VN">VU#466161</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1911" source="VUPEN" patch="1" adv="1">ADV-2009-1911</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1909" source="VUPEN" patch="1" adv="1">ADV-2009-1909</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1908" source="VUPEN" patch="1" adv="1">ADV-2009-1908</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1900" source="VUPEN" patch="1" adv="1">ADV-2009-1900</ref>
      <ref url="http://www.securityfocus.com/bid/35671" source="BID" patch="1">35671</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?rs=180&amp;uid=swg21384925" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?rs=180&amp;uid=swg21384925</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?rs=180&amp;context=SSEQTP&amp;dc=D400&amp;uid=swg24023723&amp;loc=en_US&amp;cs=UTF-8&amp;lang=en&amp;rss=ct180websphere" source="AIXAPAR" patch="1" adv="1">PK80627</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?rs=180&amp;context=SSEQTP&amp;dc=D400&amp;uid=swg24023545&amp;loc=en_US&amp;cs=UTF-8&amp;lang=en&amp;rss=ct180websphere" source="AIXAPAR" patch="1" adv="1">PK80596</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00505.html" source="FEDORA">FEDORA-2009-8473</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00494.html" source="FEDORA">FEDORA-2009-8456</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00325.html" source="FEDORA">FEDORA-2009-8337</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00310.html" source="FEDORA">FEDORA-2009-8329</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1650.html" source="REDHAT">RHSA-2009:1650</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1649.html" source="REDHAT">RHSA-2009:1649</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1637.html" source="REDHAT">RHSA-2009:1637</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1636.html" source="REDHAT">RHSA-2009:1636</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1428.html" source="REDHAT">RHSA-2009:1428</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1201.html" source="REDHAT">RHSA-2009:1201</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1200.html" source="REDHAT">RHSA-2009:1200</ref>
      <ref url="https://issues.apache.org/bugzilla/show_bug.cgi?id=47527" source="CONFIRM">https://issues.apache.org/bugzilla/show_bug.cgi?id=47527</ref>
      <ref url="https://issues.apache.org/bugzilla/show_bug.cgi?id=47526" source="CONFIRM">https://issues.apache.org/bugzilla/show_bug.cgi?id=47526</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=511915" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=511915</ref>
      <ref url="http://www.w3.org/QA/2009/07/hmac_truncation_in_xml_signatu.html" source="MISC" adv="1">http://www.w3.org/QA/2009/07/hmac_truncation_in_xml_signatu.html</ref>
      <ref url="http://www.w3.org/2008/06/xmldsigcore-errata.html#e03" source="CONFIRM" adv="1">http://www.w3.org/2008/06/xmldsigcore-errata.html#e03</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0635" source="VUPEN">ADV-2010-0635</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0366" source="VUPEN">ADV-2010-0366</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3122" source="VUPEN">ADV-2009-3122</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2543" source="VUPEN">ADV-2009-2543</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-826-1" source="UBUNTU">USN-826-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-903-1" source="UBUNTU">USN-903-1</ref>
      <ref url="http://www.securitytracker.com/id?1022661" source="SECTRACK">1022661</ref>
      <ref url="http://www.securitytracker.com/id?1022567" source="SECTRACK">1022567</ref>
      <ref url="http://www.securitytracker.com/id?1022561" source="SECTRACK">1022561</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1694.html" source="REDHAT">RHSA-2009:1694</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpuoct2009-096303.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpuoct2009-096303.html</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujul2009-091332.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujul2009-091332.html</ref>
      <ref url="http://www.openoffice.org/security/cves/CVE-2009-0217.html" source="CONFIRM">http://www.openoffice.org/security/cves/CVE-2009-0217.html</ref>
      <ref url="http://www.mono-project.com/Vulnerabilities" source="CONFIRM" adv="1">http://www.mono-project.com/Vulnerabilities</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-041.mspx" source="MS">MS10-041</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:209" source="MANDRIVA">MDVSA-2009:209</ref>
      <ref url="http://www.kb.cert.org/vuls/id/WDON-7TY529" source="CONFIRM">http://www.kb.cert.org/vuls/id/WDON-7TY529</ref>
      <ref url="http://www.kb.cert.org/vuls/id/MAPG-7TSKXQ" source="CONFIRM">http://www.kb.cert.org/vuls/id/MAPG-7TSKXQ</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1995" source="DEBIAN">DSA-1995</ref>
      <ref url="http://www.aleksey.com/xmlsec/" source="CONFIRM">http://www.aleksey.com/xmlsec/</ref>
      <ref url="http://svn.apache.org/viewvc?revision=794013&amp;view=revision" source="CONFIRM">http://svn.apache.org/viewvc?revision=794013&amp;view=revision</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020710.1-1" source="SUNALERT">1020710</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-269208-1" source="SUNALERT">269208</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-263429-1" source="SUNALERT">263429</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1" source="CONFIRM">http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1</ref>
      <ref url="http://secunia.com/advisories/38921" source="SECUNIA">38921</ref>
      <ref url="http://secunia.com/advisories/38695" source="SECUNIA">38695</ref>
      <ref url="http://secunia.com/advisories/38568" source="SECUNIA">38568</ref>
      <ref url="http://secunia.com/advisories/38567" source="SECUNIA">38567</ref>
      <ref url="http://secunia.com/advisories/37841" source="SECUNIA">37841</ref>
      <ref url="http://secunia.com/advisories/37671" source="SECUNIA">37671</ref>
      <ref url="http://secunia.com/advisories/37300" source="SECUNIA">37300</ref>
      <ref url="http://secunia.com/advisories/36494" source="SECUNIA" adv="1">36494</ref>
      <ref url="http://secunia.com/advisories/36180" source="SECUNIA" adv="1">36180</ref>
      <ref url="http://secunia.com/advisories/36176" source="SECUNIA" adv="1">36176</ref>
      <ref url="http://secunia.com/advisories/36162" source="SECUNIA" adv="1">36162</ref>
      <ref url="http://secunia.com/advisories/35858" source="SECUNIA" adv="1">35858</ref>
      <ref url="http://secunia.com/advisories/35855" source="SECUNIA" adv="1">35855</ref>
      <ref url="http://secunia.com/advisories/35854" source="SECUNIA" adv="1">35854</ref>
      <ref url="http://secunia.com/advisories/35853" source="SECUNIA" adv="1">35853</ref>
      <ref url="http://secunia.com/advisories/35852" source="SECUNIA" adv="1">35852</ref>
      <ref url="http://secunia.com/advisories/35776" source="SECUNIA" adv="1">35776</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8717" source="OVAL">oval:org.mitre.oval:def:8717</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7158" source="OVAL">oval:org.mitre.oval:def:7158</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10186" source="OVAL">oval:org.mitre.oval:def:10186</ref>
      <ref url="http://osvdb.org/55907" source="OSVDB">55907</ref>
      <ref url="http://osvdb.org/55895" source="OSVDB">55895</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=125787273209737&amp;w=2" source="HP">HPSBUX02476</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=125787273209737&amp;w=2" source="HP">HPSBUX02476</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00005.html" source="SUSE">SUSE-SA:2010:017</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00002.html" source="SUSE">SUSE-SA:2009:053</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00000.html" source="APPLE">APPLE-SA-2009-09-03-1</ref>
      <ref url="http://git.gnome.org/cgit/xmlsec/patch/?id=34b349675af9f72eb822837a8772cc1ead7115c7" source="CONFIRM">http://git.gnome.org/cgit/xmlsec/patch/?id=34b349675af9f72eb822837a8772cc1ead7115c7</ref>
      <ref url="http://git.gnome.org/cgit/xmlsec/commit/?id=34b349675af9f72eb822837a8772cc1ead7115c7" source="CONFIRM">http://git.gnome.org/cgit/xmlsec/commit/?id=34b349675af9f72eb822837a8772cc1ead7115c7</ref>
      <ref url="http://blogs.sun.com/security/entry/cert_vulnerability_note_vu_466161" source="CONFIRM">http://blogs.sun.com/security/entry/cert_vulnerability_note_vu_466161</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.0"/>
        <vers num="6.0.0.1"/>
        <vers num="6.0.0.2"/>
        <vers num="6.0.0.3"/>
        <vers num="6.0.1"/>
        <vers num="6.0.1.1"/>
        <vers num="6.0.1.11"/>
        <vers num="6.0.1.13"/>
        <vers num="6.0.1.15"/>
        <vers num="6.0.1.17"/>
        <vers num="6.0.1.2"/>
        <vers num="6.0.1.3"/>
        <vers num="6.0.1.5"/>
        <vers num="6.0.1.7"/>
        <vers num="6.0.1.9"/>
        <vers num="6.0.2" edition=""/>
        <vers num="6.0.2" edition=":fp17"/>
        <vers num="6.0.2.1"/>
        <vers num="6.0.2.10"/>
        <vers num="6.0.2.11"/>
        <vers num="6.0.2.12"/>
        <vers num="6.0.2.13"/>
        <vers num="6.0.2.14"/>
        <vers num="6.0.2.15"/>
        <vers num="6.0.2.16"/>
        <vers num="6.0.2.17"/>
        <vers num="6.0.2.18"/>
        <vers num="6.0.2.19"/>
        <vers num="6.0.2.2"/>
        <vers num="6.0.2.20"/>
        <vers num="6.0.2.21"/>
        <vers num="6.0.2.22"/>
        <vers num="6.0.2.23"/>
        <vers num="6.0.2.24"/>
        <vers num="6.0.2.25"/>
        <vers num="6.0.2.28"/>
        <vers num="6.0.2.29"/>
        <vers num="6.0.2.3"/>
        <vers num="6.0.2.30"/>
        <vers num="6.0.2.31"/>
        <vers num="6.0.2.32"/>
        <vers num="6.0.2.33"/>
        <vers num="6.1"/>
        <vers num="6.1.0"/>
        <vers num="6.1.0.0"/>
        <vers num="6.1.0.1"/>
        <vers num="6.1.0.10"/>
        <vers num="6.1.0.11"/>
        <vers num="6.1.0.12"/>
        <vers num="6.1.0.13"/>
        <vers num="6.1.0.14"/>
        <vers num="6.1.0.15"/>
        <vers num="6.1.0.16"/>
        <vers num="6.1.0.17"/>
        <vers num="6.1.0.18"/>
        <vers num="6.1.0.19"/>
        <vers num="6.1.0.2"/>
        <vers num="6.1.0.20"/>
        <vers num="6.1.0.21"/>
        <vers num="6.1.0.22"/>
        <vers num="6.1.0.23"/>
        <vers num="6.1.0.3"/>
        <vers num="6.1.0.4"/>
        <vers num="6.1.0.5"/>
        <vers num="6.1.0.6"/>
        <vers num="6.1.0.7"/>
        <vers num="6.1.0.8"/>
        <vers num="6.1.0.9"/>
        <vers num="7.0"/>
        <vers num="7.0.0.1"/>
      </prod>
      <prod vendor="mono_project" name="mono">
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.9"/>
        <vers num="2.0"/>
      </prod>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.3"/>
        <vers num="10.1.3.4"/>
        <vers num="10.1.4.3im"/>
      </prod>
      <prod vendor="oracle" name="bea_product_suite">
        <vers num="10.0" edition="mp1"/>
        <vers num="10.3"/>
        <vers num="8.1" edition="sp6"/>
        <vers num="9.0"/>
        <vers num="9.1"/>
        <vers num="9.2" edition="mp3"/>
      </prod>
      <prod vendor="oracle" name="weblogic_server_component">
        <vers num="10.0" edition="mp1"/>
        <vers num="10.3"/>
        <vers num="8.1" edition="sp6"/>
        <vers num="9.0"/>
        <vers num="9.1"/>
        <vers num="9.2" edition="mp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0218" published="2009-04-13" name="CVE-2009-0218" modified="2009-04-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Insecure method vulnerability in Particle Software IntraLaunch Application Launcher ActiveX control in IntraLaunch.ocx, as used in LDRA TBbrowse and possibly other products, allows remote attackers to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/WDON-7Q4RZN" source="MISC">http://www.kb.cert.org/vuls/id/WDON-7Q4RZN</ref>
      <ref url="http://www.kb.cert.org/vuls/id/MAPG-7PYRP4" source="CONFIRM">http://www.kb.cert.org/vuls/id/MAPG-7PYRP4</ref>
      <ref url="http://www.kb.cert.org/vuls/id/908801" source="CERT-VN">VU#908801</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49684" source="XF">intralaunch-activex-code-execution(49684)</ref>
      <ref url="http://www.securityfocus.com/bid/34395" source="BID">34395</ref>
    </refs>
    <vuln_soft>
      <prod vendor="particlesoftware" name="intralaunch">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0219" published="2009-01-20" name="CVE-2009-0219" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 performs delete operations on uninitialized pointers, which allows user-assisted remote attackers to execute arbitrary code via a crafted data stream in a .pdf file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1021559" source="SECTRACK">1021559</ref>
      <ref url="http://www.securityfocus.com/bid/33250" source="BID">33250</ref>
      <ref url="http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB17119" source="CONFIRM" adv="1">http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB17119</ref>
      <ref url="http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB17118" source="CONFIRM" adv="1">http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB17118</ref>
      <ref url="http://secunia.com/advisories/33534" source="SECUNIA" adv="1">33534</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=766" source="IDEFENSE">20090113 RIM BlackBerry Enterprise Server Attachment Service PDF Distiller Uninitialized Memory Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="research_in_motion_limited" name="blackberry_enterprise_server">
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.1.6"/>
      </prod>
      <prod vendor="research_in_motion_limited" name="blackberry_professional_software">
        <vers num="4.1.4"/>
      </prod>
      <prod vendor="research_in_motion_limited" name="blackberry_unite">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers prev="1" num="1.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0220" published="2009-05-12" name="CVE-2009-0220" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the PowerPoint 4.0 importer (PP4X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allow remote attackers to execute arbitrary code via crafted formatting data for paragraphs in a file that uses a PowerPoint 4.0 native file format, related to (1) an incorrect calculation from a record header, or (2) an interget that is used to specify the number of bytes to copy, aka "Legacy File Format Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-132A.html" source="CERT">TA09-132A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-017.mspx" source="MS" patch="1" adv="1">MS09-017</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1290" source="VUPEN" adv="1">ADV-2009-1290</ref>
      <ref url="http://www.securitytracker.com/id?1022205" source="SECTRACK">1022205</ref>
      <ref url="http://www.securityfocus.com/bid/34833" source="BID">34833</ref>
      <ref url="http://secunia.com/advisories/32428" source="SECUNIA" adv="1">32428</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5610" source="OVAL">oval:org.mitre.oval:def:5610</ref>
      <ref url="http://osvdb.org/54386" source="OSVDB">54386</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=790" source="IDEFENSE">20090512 Microsoft PowerPoint PPT 4.0 Importer Multiple Stack Buffer Overflow Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_powerpoint">
        <vers num="2000" edition="sp3"/>
        <vers num="2002" edition="sp3"/>
        <vers num="2003" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0221" published="2009-05-12" name="CVE-2009-0221" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a PowerPoint file containing a crafted record type for "collaboration information for different slides" that contains a field that specifies a large number of records, which triggers an under-allocated buffer and a heap-based buffer overflow, aka "Integer Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-132A.html" source="CERT">TA09-132A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-017.mspx" source="MS" patch="1" adv="1">MS09-017</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1290" source="VUPEN">ADV-2009-1290</ref>
      <ref url="http://www.securitytracker.com/id?1022205" source="SECTRACK">1022205</ref>
      <ref url="http://www.securityfocus.com/bid/34835" source="BID">34835</ref>
      <ref url="http://secunia.com/advisories/32428" source="SECUNIA">32428</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6127" source="OVAL">oval:org.mitre.oval:def:6127</ref>
      <ref url="http://osvdb.org/54394" source="OSVDB">54394</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=796" source="IDEFENSE">20090512 Microsoft PowerPoint Integer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_powerpoint">
        <vers num="2002" edition="sp3"/>
        <vers num="2003" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0222" published="2009-05-12" name="CVE-2009-0222" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to a "pointer overwrite" and memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0223, CVE-2009-0226, CVE-2009-0227, and CVE-2009-1137.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-132A.html" source="CERT">TA09-132A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-017.mspx" source="MS" patch="1" adv="1">MS09-017</ref>
      <ref url="http://www.vupen.com/exploits/Microsoft_PowerPoint_Pointer_Overwrite_Code_Execution_Exploit_MS09_017_1290123.php" source="MISC" adv="1">http://www.vupen.com/exploits/Microsoft_PowerPoint_Pointer_Overwrite_Code_Execution_Exploit_MS09_017_1290123.php</ref>
      <ref url="http://www.vupen.com/exploits/Microsoft_PowerPoint_Memory_Corruption_Code_Execution_Exploit_MS09_017_1290124.php" source="MISC" adv="1">http://www.vupen.com/exploits/Microsoft_PowerPoint_Memory_Corruption_Code_Execution_Exploit_MS09_017_1290124.php</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1290" source="VUPEN">ADV-2009-1290</ref>
      <ref url="http://www.securitytracker.com/id?1022205" source="SECTRACK">1022205</ref>
      <ref url="http://www.securityfocus.com/bid/34831" source="BID">34831</ref>
      <ref url="http://secunia.com/advisories/32428" source="SECUNIA">32428</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6143" source="OVAL">oval:org.mitre.oval:def:6143</ref>
      <ref url="http://osvdb.org/54382" source="OSVDB">54382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_powerpoint">
        <vers num="2000" edition="sp3"/>
        <vers num="2002" edition="sp3"/>
        <vers num="2003" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0223" published="2009-05-12" name="CVE-2009-0223" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0226, CVE-2009-0227, and CVE-2009-1137.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-132A.html" source="CERT">TA09-132A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-017.mspx" source="MS" patch="1" adv="1">MS09-017</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1290" source="VUPEN">ADV-2009-1290</ref>
      <ref url="http://www.securitytracker.com/id?1022205" source="SECTRACK">1022205</ref>
      <ref url="http://www.securityfocus.com/bid/34834" source="BID">34834</ref>
      <ref url="http://secunia.com/advisories/32428" source="SECUNIA">32428</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6269" source="OVAL">oval:org.mitre.oval:def:6269</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_powerpoint">
        <vers num="2000" edition="sp3"/>
        <vers num="2002" edition="sp3"/>
        <vers num="2003" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0224" published="2009-05-12" name="CVE-2009-0224" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; PowerPoint Viewer 2003 and 2007 SP1 and SP2; PowerPoint in Microsoft Office 2004 for Mac and 2008 for Mac; Open XML File Format Converter for Mac; Microsoft Works 8.5 and 9.0; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly validate PowerPoint files, which allows remote attackers to execute arbitrary code via multiple crafted BuildList records that include ChartBuild containers, which triggers memory corruption, aka "Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-132A.html" source="CERT">TA09-132A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-017.mspx" source="MS" patch="1" adv="1">MS09-017</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1290" source="VUPEN">ADV-2009-1290</ref>
      <ref url="http://www.securitytracker.com/id?1022205" source="SECTRACK">1022205</ref>
      <ref url="http://www.securityfocus.com/bid/34879" source="BID">34879</ref>
      <ref url="http://secunia.com/advisories/32428" source="SECUNIA">32428</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6023" source="OVAL">oval:org.mitre.oval:def:6023</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=793" source="IDEFENSE">20090512 Microsoft PowerPoint Build List Memory Corruption Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="compatibility_pack_word_excel_powerpoint">
        <vers num="2007" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack_for_word_excel_ppt_2007">
        <vers num="" edition=":sp1"/>
        <vers num="" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="office_powerpoint">
        <vers num="2000" edition="sp3"/>
        <vers num="2002" edition="sp3"/>
        <vers num="2003" edition="sp3"/>
        <vers num="2007" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="office_powerpoint_viewer">
        <vers num="2003"/>
        <vers num="2007" edition="sp1"/>
        <vers num="2007" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac"/>
      </prod>
      <prod vendor="microsoft" name="powerpoint">
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
        <vers num="2008" edition=""/>
        <vers num="2008" edition=":mac"/>
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="8.5"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0225" published="2009-05-12" name="CVE-2009-0225" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office PowerPoint 2002 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to improper "array indexing" and memory corruption, aka "PP7 Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-132A.html" source="CERT">TA09-132A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-017.mspx" source="MS" patch="1" adv="1">MS09-017</ref>
      <ref url="http://www.vupen.com/exploits/Microsoft_PowerPoint_Array_Indexing_Code_Execution_Exploit_MS09_017_1290125.php" source="MISC" adv="1">http://www.vupen.com/exploits/Microsoft_PowerPoint_Array_Indexing_Code_Execution_Exploit_MS09_017_1290125.php</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1290" source="VUPEN">ADV-2009-1290</ref>
      <ref url="http://www.securitytracker.com/id?1022205" source="SECTRACK">1022205</ref>
      <ref url="http://www.securityfocus.com/bid/34880" source="BID">34880</ref>
      <ref url="http://secunia.com/advisories/32428" source="SECUNIA">32428</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5526" source="OVAL">oval:org.mitre.oval:def:5526</ref>
      <ref url="http://osvdb.org/54388" source="OSVDB">54388</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_powerpoint">
        <vers num="2002" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0226" published="2009-05-12" name="CVE-2009-0226" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the PowerPoint 4.2 conversion filter in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via a long string in sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0227, and CVE-2009-1137.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-132A.html" source="CERT">TA09-132A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-017.mspx" source="MS" patch="1" adv="1">MS09-017</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1290" source="VUPEN" adv="1">ADV-2009-1290</ref>
      <ref url="http://www.securitytracker.com/id?1022205" source="SECTRACK">1022205</ref>
      <ref url="http://www.securityfocus.com/bid/34881" source="BID">34881</ref>
      <ref url="http://secunia.com/advisories/32428" source="SECUNIA" adv="1">32428</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6106" source="OVAL">oval:org.mitre.oval:def:6106</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=789" source="IDEFENSE">20090512 Microsoft PowerPoint 4.2 Conversion Filter Stack Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_powerpoint">
        <vers num="2000" edition="sp3"/>
        <vers num="2002" edition="sp3"/>
        <vers num="2003" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0227" published="2009-05-12" name="CVE-2009-0227" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the PowerPoint 4.2 conversion filter (PP4X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via a large number of structures in sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0226, and CVE-2009-1137.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-132A.html" source="CERT">TA09-132A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-017.mspx" source="MS" patch="1" adv="1">MS09-017</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1290" source="VUPEN" adv="1">ADV-2009-1290</ref>
      <ref url="http://www.securitytracker.com/id?1022205" source="SECTRACK">1022205</ref>
      <ref url="http://www.securityfocus.com/bid/34882" source="BID">34882</ref>
      <ref url="http://secunia.com/advisories/32428" source="SECUNIA" adv="1">32428</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6239" source="OVAL">oval:org.mitre.oval:def:6239</ref>
      <ref url="http://osvdb.org/54384" source="OSVDB">54384</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=787" source="IDEFENSE">20090512 Microsoft PowerPoint 4.2 Conversion Filter Stack Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_powerpoint">
        <vers num="2000" edition="sp3"/>
        <vers num="2002" edition="sp3"/>
        <vers num="2003" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0228" published="2009-06-10" name="CVE-2009-0228" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the EnumeratePrintShares function in Windows Print Spooler Service (win32spl.dll) in Microsoft Windows 2000 SP4 allows remote printer servers to execute arbitrary code via a a crafted ShareName in a response to an RPC request, related to "printing data structures," aka "Buffer Overflow in Print Spooler Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-022.mspx" source="MS" patch="1" adv="1">MS09-022</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1541" source="VUPEN">ADV-2009-1541</ref>
      <ref url="http://www.securitytracker.com/id?1022352" source="SECTRACK">1022352</ref>
      <ref url="http://www.securityfocus.com/bid/35206" source="BID">35206</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-217.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-217.htm</ref>
      <ref url="http://secunia.com/advisories/35365" source="SECUNIA">35365</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6317" source="OVAL">oval:org.mitre.oval:def:6317</ref>
      <ref url="http://osvdb.org/54932" source="OSVDB">54932</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=806" source="IDEFENSE">20090609 Microsoft Windows 2000 Print Spooler Remote Stack Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0229" published="2009-06-10" name="CVE-2009-0229" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The Windows Printing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows local users to read arbitrary files via a crafted separator page, aka "Print Spooler Read File Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-022.mspx" source="MS" patch="1" adv="1">MS09-022</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1541" source="VUPEN">ADV-2009-1541</ref>
      <ref url="http://www.securitytracker.com/id?1022352" source="SECTRACK">1022352</ref>
      <ref url="http://www.securityfocus.com/bid/35208" source="BID">35208</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-217.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-217.htm</ref>
      <ref url="http://secunia.com/advisories/35365" source="SECUNIA">35365</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5815" source="OVAL">oval:org.mitre.oval:def:5815</ref>
      <ref url="http://osvdb.org/54933" source="OSVDB">54933</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="sp4"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="sp2" edition=""/>
        <vers num="sp2" edition=":itanium"/>
        <vers num="sp2" edition=":x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:itanium"/>
        <vers num="-" edition="x32"/>
        <vers num="sp2" edition="x32"/>
        <vers num="sp2" edition="x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="gold"/>
        <vers num="sp1"/>
        <vers num="sp2"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
        <vers num="sp2"/>
        <vers num="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0230" published="2009-06-10" name="CVE-2009-0230" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">The Windows Print Spooler in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows remote authenticated users to gain privileges via a crafted RPC message that triggers loading of a DLL file from an arbitrary directory, aka "Print Spooler Load Library Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-022.mspx" source="MS" patch="1" adv="1">MS09-022</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1541" source="VUPEN">ADV-2009-1541</ref>
      <ref url="http://www.securitytracker.com/id?1022352" source="SECTRACK">1022352</ref>
      <ref url="http://www.securityfocus.com/bid/35209" source="BID">35209</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-217.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-217.htm</ref>
      <ref url="http://secunia.com/advisories/35365" source="SECUNIA">35365</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6287" source="OVAL">oval:org.mitre.oval:def:6287</ref>
      <ref url="http://osvdb.org/54934" source="OSVDB">54934</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server">
        <vers num="2008" edition=""/>
        <vers num="2008" edition=":"/>
        <vers num="2008" edition="::itanium"/>
        <vers num="2008" edition=":sp2"/>
        <vers num="2008" edition=":sp2:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64"/>
        <vers num="" edition=":x32"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x32"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0231" published="2009-07-15" name="CVE-2009-0231" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Embedded OpenType (EOT) Font Engine (T2EMBED.DLL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table in a data record that triggers an integer truncation and a heap-based buffer overflow, aka "Embedded OpenType Font Heap Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-195A.html" source="CERT">TA09-195A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-029.mspx" source="MS" patch="1" adv="1">MS09-029</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1887" source="VUPEN" adv="1">ADV-2009-1887</ref>
      <ref url="http://www.securitytracker.com/id?1022543" source="SECTRACK">1022543</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5457" source="OVAL">oval:org.mitre.oval:def:5457</ref>
      <ref url="http://osvdb.org/55842" source="OSVDB">55842</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=811" source="IDEFENSE">20090714 Microsoft Embedded OpenType Font Engine (T2EMBED.DLL) Heap Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium"/>
        <vers num="" edition=":x64"/>
        <vers num="" edition=":x32"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x32"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="-" edition="sp1"/>
        <vers num="-" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:professional_x64"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0232" published="2009-07-15" name="CVE-2009-0232" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table, aka "Embedded OpenType Font Integer Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-195A.html" source="CERT">TA09-195A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-029.mspx" source="MS" patch="1" adv="1">MS09-029</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1887" source="VUPEN">ADV-2009-1887</ref>
      <ref url="http://www.securitytracker.com/id?1022543" source="SECTRACK">1022543</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5678" source="OVAL">oval:org.mitre.oval:def:5678</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium"/>
        <vers num="" edition=":x64"/>
        <vers num="" edition=":x32"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x32"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="-" edition="sp1"/>
        <vers num="-" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:professional_x64"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0233" published="2009-03-11" name="CVE-2009-0233" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not reuse cached DNS responses in all applicable situations, which makes it easier for remote attackers to predict transaction IDs and poison caches by simultaneously sending crafted DNS queries and responses, aka "DNS Server Query Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-069A.html" source="CERT">TA09-069A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-008.mspx" source="MS" patch="1" adv="1">MS09-008</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0661" source="VUPEN">ADV-2009-0661</ref>
      <ref url="http://www.securitytracker.com/id?1021831" source="SECTRACK">1021831</ref>
      <ref url="http://www.securityfocus.com/bid/33982" source="BID">33982</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-083.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-083.htm</ref>
      <ref url="http://secunia.com/advisories/34217" source="SECUNIA">34217</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6228" source="OVAL">oval:org.mitre.oval:def:6228</ref>
      <ref url="http://osvdb.org/52517" source="OSVDB">52517</ref>
      <ref url="http://blogs.technet.com/srd/archive/2009/03/13/ms09-008-dns-and-wins-server-security-update-in-more-detail.aspx" source="CONFIRM">http://blogs.technet.com/srd/archive/2009/03/13/ms09-008-dns-and-wins-server-security-update-in-more-detail.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:itanium"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0234" published="2009-03-11" name="CVE-2009-0234" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 does not properly cache crafted DNS responses, which makes it easier for remote attackers to predict transaction IDs and poison caches by sending many crafted DNS queries that trigger "unnecessary lookups," aka "DNS Server Response Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-069A.html" source="CERT">TA09-069A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/319331" source="CERT-VN">VU#319331</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-008.mspx" source="MS" patch="1" adv="1">MS09-008</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0661" source="VUPEN">ADV-2009-0661</ref>
      <ref url="http://www.securitytracker.com/id?1021831" source="SECTRACK">1021831</ref>
      <ref url="http://www.securityfocus.com/bid/33988" source="BID">33988</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-083.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-083.htm</ref>
      <ref url="http://secunia.com/advisories/34217" source="SECUNIA">34217</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5715" source="OVAL">oval:org.mitre.oval:def:5715</ref>
      <ref url="http://osvdb.org/52518" source="OSVDB">52518</ref>
      <ref url="http://blogs.technet.com/srd/archive/2009/03/13/ms09-008-dns-and-wins-server-security-update-in-more-detail.aspx" source="CONFIRM">http://blogs.technet.com/srd/archive/2009/03/13/ms09-008-dns-and-wins-server-security-update-in-more-detail.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:itanium"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0235" published="2009-04-15" name="CVE-2009-0235" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the Word 97 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Word 97 file that triggers memory corruption, related to use of inconsistent integer data sizes for an unspecified length field, aka "WordPad Word 97 Text Converter Stack Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-010.mspx" source="MS" patch="1" adv="1">MS09-010</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1024" source="VUPEN">ADV-2009-1024</ref>
      <ref url="http://www.securitytracker.com/id?1022043" source="SECTRACK">1022043</ref>
      <ref url="http://www.securityfocus.com/bid/34470" source="BID">34470</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5893" source="OVAL">oval:org.mitre.oval:def:5893</ref>
      <ref url="http://osvdb.org/53664" source="OSVDB">53664</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=783" source="IDEFENSE">20090414 Microsoft WordPad Word97 Converter Stack Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0237" published="2009-04-15" name="CVE-2009-0237" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in cookieauth.dll in the HTML forms authentication component in Microsoft Forefront Threat Management Gateway, Medium Business Edition (TMG MBE); and Internet Security and Acceleration (ISA) Server 2006, 2006 Supportability Update, and 2006 SP1; allows remote attackers to inject arbitrary web script or HTML via "authentication input" to this component, aka "Cross-Site Scripting Vulnerability."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-016.mspx" source="MS" patch="1" adv="1">MS09-016</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1030" source="VUPEN">ADV-2009-1030</ref>
      <ref url="http://www.securitytracker.com/id?1022046" source="SECTRACK">1022046</ref>
      <ref url="http://secunia.com/advisories/34687" source="SECUNIA">34687</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5771" source="OVAL">oval:org.mitre.oval:def:5771</ref>
      <ref url="http://osvdb.org/53637" source="OSVDB">53637</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="forefront_threat_management_gateway">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:medium_business"/>
      </prod>
      <prod vendor="microsoft" name="internet_security_and_acceleration_server">
        <vers num="2004" edition="sp3"/>
        <vers num="2004" edition="sp3:enterprise"/>
        <vers num="2004" edition="sp3:standard"/>
        <vers num="2006" edition="sp1"/>
        <vers num="2006" edition="supportability"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0238" published="2009-02-25" name="CVE-2009-0238" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an invalid object, as exploited in the wild in February 2009 by Trojan.Mdropper.AC.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48875" source="XF">ms-excel-unspecified-code-execution(48875)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1023" source="VUPEN">ADV-2009-1023</ref>
      <ref url="http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-022310-4202-99" source="MISC">http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-022310-4202-99</ref>
      <ref url="http://www.securityfocus.com/bid/33870" source="BID">33870</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms09-009.mspx" source="MS">MS09-009</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/968272.mspx" source="CONFIRM" adv="1">http://www.microsoft.com/technet/security/advisory/968272.mspx</ref>
      <ref url="http://securitytracker.com/id?1021744" source="SECTRACK">1021744</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5968" source="OVAL">oval:org.mitre.oval:def:5968</ref>
      <ref url="http://isc.sans.org/diary.html?storyid=5923" source="MISC">http://isc.sans.org/diary.html?storyid=5923</ref>
      <ref url="http://blogs.zdnet.com/security/?p=2658" source="MISC">http://blogs.zdnet.com/security/?p=2658</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2008" edition=""/>
        <vers num="2008" edition=":mac"/>
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack">
        <vers num="2007" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="office_excel">
        <vers num="2000" edition="sp3"/>
        <vers num="2002" edition="sp3"/>
        <vers num="2003" edition="sp3"/>
        <vers num="2007" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="office_excel_viewer">
        <vers num="2003" edition="gold"/>
        <vers num="2003" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0239" published="2009-06-10" name="CVE-2009-0239" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Windows Search 4.0 for Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted file that appears in a preview in a search result, aka "Script Execution in Windows Search Vulnerability."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-023.mspx" source="MS" patch="1" adv="1">MS09-023</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1542" source="VUPEN">ADV-2009-1542</ref>
      <ref url="http://www.securitytracker.com/id?1022353" source="SECTRACK">1022353</ref>
      <ref url="http://secunia.com/advisories/35366" source="SECUNIA">35366</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5428" source="OVAL">oval:org.mitre.oval:def:5428</ref>
      <ref url="http://osvdb.org/54935" source="OSVDB">54935</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_search">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0240" published="2009-01-20" name="CVE-2009-0240" modified="2011-09-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">listing.php in WebSVN 2.0 and possibly 1.7 beta, when using an SVN authz file, allows remote authenticated users to read changelogs or diffs for restricted projects via a modified repname parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48171" source="XF">websvn-listing-information-disclosure(48171)</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/18/2" source="MLIST">[oss-security] 20090118 CVE request: WebSVN</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200903-20.xml" source="GENTOO">GLSA-200903-20</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1725" source="DEBIAN">DSA-1725</ref>
      <ref url="http://secunia.com/advisories/34191" source="SECUNIA">34191</ref>
      <ref url="http://secunia.com/advisories/33945" source="SECUNIA">33945</ref>
      <ref url="http://secunia.com/advisories/32338" source="SECUNIA" adv="1">32338</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=512191" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=512191</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tigris" name="websvn">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0241" published="2009-01-21" name="CVE-2009-0241" modified="2009-06-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the process_path function in gmetad/server.c in Ganglia 3.1.1 allows remote attackers to cause a denial of service (crash) via a request to the gmetad service with a long pathname.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33299" source="BID">33299</ref>
      <ref url="http://www.mail-archive.com/ganglia-developers@lists.sourceforge.net/msg04929.html" source="MLIST">[Ganglia-developers] 20090113 patches for: [Sec] Gmetad server BoF and network overload + [Feature] multiple requests per conn on interactive port</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200903-22.xml" source="GENTOO">GLSA-200903-22</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA">35416</ref>
      <ref url="http://secunia.com/advisories/34228" source="SECUNIA">34228</ref>
      <ref url="http://secunia.com/advisories/33506" source="SECUNIA" adv="1">33506</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
      <ref url="http://bugzilla.ganglia.info/cgi-bin/bugzilla/show_bug.cgi?id=223" source="MISC">http://bugzilla.ganglia.info/cgi-bin/bugzilla/show_bug.cgi?id=223</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ganglia" name="ganglia">
        <vers num="3.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2009-0242" reject="1" published="2009-01-21" name="CVE-2009-0242" modified="2009-02-05">
    <desc>
      <descript source="cve">** REJECT **  gmetad in Ganglia 3.1.1, when supporting multiple requests per connection on an interactive port, allows remote attackers to cause a denial of service via a request to the gmetad service with a path does not exist, which causes Ganglia to (1) perform excessive CPU computation and (2) send the entire tree, which consumes network bandwidth.  NOTE: the vendor and original researcher have disputed this issue, since legitimate requests can generate the same amount of resource consumption.  CVE concurs with the dispute, so this identifier should not be used.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0243" published="2009-01-21" name="CVE-2009-0243" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Microsoft Windows does not properly enforce the Autorun and NoDriveTypeAutoRun registry values, which allows physically proximate attackers to execute arbitrary code by (1) inserting CD-ROM media, (2) inserting DVD media, (3) connecting a USB device, and (4) connecting a Firewire device; (5) allows user-assisted remote attackers to execute arbitrary code by mapping a network drive; and allows user-assisted attackers to execute arbitrary code by clicking on (6) an icon under My Computer\Devices with Removable Storage and (7) an option in an AutoPlay dialog, related to the Autorun.inf file.  NOTE: vectors 1 and 3 on Vista are already covered by CVE-2008-0951.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-020A.html" source="CERT">TA09-020A</ref>
      <ref url="http://www.securitytracker.com/id?1021629" source="SECTRACK">1021629</ref>
      <ref url="http://isc.sans.org/diary.html?storyid=5695" source="MISC">http://isc.sans.org/diary.html?storyid=5695</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:itanium"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium"/>
        <vers num="" edition=":x64"/>
        <vers num="" edition=":x32"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":professional_x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:professional_x64"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0244" published="2009-01-21" name="CVE-2009-0244" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the OBEX FTP Service in the Microsoft Bluetooth stack in Windows Mobile 6 Professional, and probably Windows Mobile 5.0 for Pocket PC and 5.0 for Pocket PC Phone Edition, allows remote authenticated users to list arbitrary directories, and create or read arbitrary files, via a .. (dot dot) in a pathname.  NOTE: this can be leveraged for code execution by writing to a Startup folder.</descript>
    </desc>
    <impacts>
      <impact source="nvd">per: http://www.seguridadmobile.com/windows-mobile/windows-mobile-security/Microsoft-Bluetooth-Stack-Directory-Traversal.html

"Non vulnerable products: Windows Mobile devices 5.0 and 6 not using Microsoft Bluetooth Stack (for example: ASUS P525, ASUS P535, ... using Widcomm/Broadcom Bluetooth Stack)"</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48124" source="XF">winmobile-obexftp-directory-traversal(48124)</ref>
      <ref url="http://www.seguridadmobile.com/windows-mobile/windows-mobile-security/Microsoft-Bluetooth-Stack-Directory-Traversal.html" source="MISC">http://www.seguridadmobile.com/windows-mobile/windows-mobile-security/Microsoft-Bluetooth-Stack-Directory-Traversal.html</ref>
      <ref url="http://www.securityfocus.com/bid/33359" source="BID">33359</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500199/100/0/threaded" source="BUGTRAQ">20090119 Microsoft Bluetooth Stack OBEX Directory Traversal</ref>
      <ref url="http://securityreason.com/securityalert/4938" source="SREASON">4938</ref>
      <ref url="http://secunia.com/advisories/33598" source="SECUNIA">33598</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_mobile">
        <vers num="5.0" edition=""/>
        <vers num="5.0" edition=":pocket_pc"/>
        <vers num="5.0" edition=":smartphone"/>
        <vers num="6.0" edition=""/>
        <vers num="6.0" edition=":standard"/>
        <vers num="6.0" edition=":pro"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0245" published="2009-01-21" name="CVE-2009-0245" modified="2009-01-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Usagi Project MyNETS 1.2.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2008-4629.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://usagi-project.org/PRESS/archives/57" source="CONFIRM" patch="1" adv="1">http://usagi-project.org/PRESS/archives/57</ref>
      <ref url="http://www.securityfocus.com/bid/33145" source="BID">33145</ref>
      <ref url="http://secunia.com/advisories/33409" source="SECUNIA" adv="1">33409</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000001.html" source="JVNDB">JVNDB-2009-000001</ref>
      <ref url="http://jvn.jp/en/jp/JVN36802959/index.html" source="JVN">JVN#36802959</ref>
    </refs>
    <vuln_soft>
      <prod vendor="usagi" name="mynets">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.1.0"/>
        <vers num="1.2.0"/>
        <vers prev="1" num="1.2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0246" published="2009-01-22" name="CVE-2009-0246" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in easyHDR PRO 1.60.2 allows user-assisted attackers to execute arbitrary code via an invalid Radiance RGBE (aka .hdr) file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48119" source="XF">easyhdrpro-hdr-bo(48119)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0190" source="VUPEN">ADV-2009-0190</ref>
      <ref url="http://www.securityfocus.com/bid/33363" source="BID">33363</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500192/100/0/threaded" source="BUGTRAQ">20090120 Secunia Research: EasyHDR Pro Radiance RGBE Buffer Overflow</ref>
      <ref url="http://securityreason.com/securityalert/4941" source="SREASON">4941</ref>
      <ref url="http://secunia.com/secunia_research/2008-61/" source="MISC" adv="1">http://secunia.com/secunia_research/2008-61/</ref>
      <ref url="http://secunia.com/advisories/33468" source="SECUNIA" adv="1">33468</ref>
      <ref url="http://osvdb.org/51609" source="OSVDB">51609</ref>
      <ref url="http://easyhdr.com/version.php" source="CONFIRM" adv="1">http://easyhdr.com/version.php</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easyhdr" name="easyhdr">
        <vers num="1.60.2" edition=""/>
        <vers num="1.60.2" edition=":pro"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0247" published="2009-01-22" name="CVE-2009-0247" modified="2009-01-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The server for 53KF Web IM 2009 Home, Professional, and Enterprise editions relies on client-side protection mechanisms against cross-site scripting (XSS), which allows remote attackers to conduct XSS attacks by using a modified client to send a crafted IM message, related to the msg variable.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48096" source="XF">53kfwebim-msg-xss(48096)</ref>
      <ref url="http://www.securityfocus.com/bid/33341" source="BID">33341</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500169/100/0/threaded" source="BUGTRAQ">20090119 53KF Web IM 2009 Cross-Site Scripting Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="53kf" name="web_im_2009">
        <vers num="_nil_" edition="enterprise"/>
        <vers num="_nil_" edition="home"/>
        <vers num="_nil_" edition="professional"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0248" published="2009-01-22" name="CVE-2009-0248" modified="2009-01-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in rankup.asp in Katy Whitton RankEm allows remote attackers to inject arbitrary web script or HTML via the siteID parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48072" source="XF">rankem-siteid-xss(48072)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48071" source="XF">rankem-rankup-xss(48071)</ref>
      <ref url="http://www.securityfocus.com/bid/33324" source="BID">33324</ref>
      <ref url="http://www.milw0rm.com/exploits/7805" source="MILW0RM">7805</ref>
    </refs>
    <vuln_soft>
      <prod vendor="katywhitton" name="rankem">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0249" published="2009-01-22" name="CVE-2009-0249" modified="2009-01-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Katy Whitton RankEm stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for database/topsites.mdb.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48070" source="XF">rankem-topsites-information-disclosure(48070)</ref>
      <ref url="http://www.milw0rm.com/exploits/7805" source="MILW0RM">7805</ref>
    </refs>
    <vuln_soft>
      <prod vendor="katywhitton" name="rankem">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0250" published="2009-01-22" name="CVE-2009-0250" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ryneezy phoSheezy 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the file containing the administrator's password hash via a direct request for config/password.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48056" source="XF">phosheezy-configpassword-info-disclosure(48056)</ref>
      <ref url="http://www.milw0rm.com/exploits/7780" source="MILW0RM">7780</ref>
      <ref url="http://securityreason.com/securityalert/4935" source="SREASON">4935</ref>
      <ref url="http://secunia.com/advisories/33531" source="SECUNIA" adv="1">33531</ref>
      <ref url="http://osvdb.org/51411" source="OSVDB">51411</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ryneezy" name="phosheezy">
        <vers num="0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0251" published="2009-01-22" name="CVE-2009-0251" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into config/footer via the footer parameter.  NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2009-0250. NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/7780" source="MILW0RM">7780</ref>
      <ref url="http://securityreason.com/securityalert/4935" source="SREASON">4935</ref>
      <ref url="http://secunia.com/advisories/33531" source="SECUNIA" adv="1">33531</ref>
      <ref url="http://osvdb.org/51412" source="OSVDB">51412</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ryneezy" name="phosheezy">
        <vers num="0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0252" published="2009-01-22" name="CVE-2009-0252" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in default.asp in Enthrallweb eReservations allow remote attackers to execute arbitrary SQL commands via the (1) Login parameter (aka username field) or the (2) Password parameter (aka password field).  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48062" source="XF">ereservations-login-sql-injection(48062)</ref>
      <ref url="http://www.securityfocus.com/bid/33321" source="BID">33321</ref>
      <ref url="http://www.milw0rm.com/exploits/7801" source="MILW0RM">7801</ref>
      <ref url="http://secunia.com/advisories/33578" source="SECUNIA" adv="1">33578</ref>
      <ref url="http://osvdb.org/51456" source="OSVDB">51456</ref>
    </refs>
    <vuln_soft>
      <prod vendor="enthrallweb" name="ereservations">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0253" published="2009-01-22" name="CVE-2009-0253" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Mozilla Firefox 3.0.5 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Status Bar Obfuscation" and "Clickjacking" attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48212" source="XF">firefox-onclickaction-click-hijacking(48212)</ref>
      <ref url="http://www.milw0rm.com/exploits/7842" source="MILW0RM">7842</ref>
      <ref url="http://securityreason.com/securityalert/4936" source="SREASON">4936</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0254" published="2009-01-22" name="CVE-2009-0254" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in easyHDR PRO 1.60.2 allows user-assisted attackers to execute arbitrary code via an invalid Flexible Image Transport System (FITS) file.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0190" source="VUPEN">ADV-2009-0190</ref>
      <ref url="http://www.securityfocus.com/bid/33363" source="BID">33363</ref>
      <ref url="http://secunia.com/advisories/33468" source="SECUNIA" adv="1">33468</ref>
      <ref url="http://osvdb.org/51608" source="OSVDB">51608</ref>
      <ref url="http://easyhdr.com/version.php" source="CONFIRM" adv="1">http://easyhdr.com/version.php</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easyhdr" name="easyhdr">
        <vers num="1.60.2" edition=""/>
        <vers num="1.60.2" edition=":pro"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0255" published="2009-01-22" name="CVE-2009-0255" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The System extension Install tool in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 creates the encryption key with an insufficiently random seed, which makes it easier for attackers to crack the key.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48132" source="XF">typo3-installtool-weak-security(48132)</ref>
      <ref url="http://www.securityfocus.com/bid/33376" source="BID">33376</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1711" source="DEBIAN">DSA-1711</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-001/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-001/</ref>
      <ref url="http://secunia.com/advisories/33679" source="SECUNIA" adv="1">33679</ref>
      <ref url="http://secunia.com/advisories/33617" source="SECUNIA" adv="1">33617</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="typo3">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="4.0.8"/>
        <vers num="4.0.9"/>
        <vers num="4.1.0" edition="beta1"/>
        <vers num="4.1.0" edition="rc1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.1.6"/>
        <vers num="4.1.7"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0256" published="2009-01-22" name="CVE-2009-0256" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Session fixation vulnerability in the authentication library in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote attackers to hijack web sessions via unspecified vectors related to (1) frontend and (2) backend authentication.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48133" source="XF">typo3-library-session-hijacking(48133)</ref>
      <ref url="http://www.securityfocus.com/bid/33376" source="BID">33376</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1711" source="DEBIAN">DSA-1711</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-001/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-001/</ref>
      <ref url="http://secunia.com/advisories/33679" source="SECUNIA">33679</ref>
      <ref url="http://secunia.com/advisories/33617" source="SECUNIA" adv="1">33617</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="typo3">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="4.0.8"/>
        <vers num="4.0.9"/>
        <vers num="4.1.0" edition="beta1"/>
        <vers num="4.1.0" edition="rc1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.1.6"/>
        <vers num="4.1.7"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0257" published="2009-01-22" name="CVE-2009-0257" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) content of indexed files to the (a) Indexed Search Engine (indexed_search) system extension; (b) unspecified test scripts in the ADOdb system extension; and (c) unspecified vectors in the Workspace module.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48137" source="XF">typo3-adodb-xss(48137)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48136" source="XF">typo3-workspace-xss(48136)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48135" source="XF">typo3-indexedsearchengine-xss(48135)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48133" source="XF">typo3-library-session-hijacking(48133)</ref>
      <ref url="http://www.securityfocus.com/bid/33376" source="BID">33376</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1711" source="DEBIAN">DSA-1711</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-001/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-001/</ref>
      <ref url="http://secunia.com/advisories/33679" source="SECUNIA">33679</ref>
      <ref url="http://secunia.com/advisories/33617" source="SECUNIA" adv="1">33617</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="typo3">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="4.0.8"/>
        <vers num="4.0.9"/>
        <vers num="4.1.0" edition="beta1"/>
        <vers num="4.1.0" edition="rc1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.1.6"/>
        <vers num="4.1.7"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0258" published="2009-01-22" name="CVE-2009-0258" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Indexed Search Engine (indexed_search) system extension in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote attackers to execute arbitrary commands via a crafted filename containing shell metacharacters, which is not properly handled by the command-line indexer.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48138" source="XF">typo3-indexedsearch-command-execution(48138)</ref>
      <ref url="http://www.securityfocus.com/bid/33376" source="BID">33376</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/23/4" source="MLIST">[oss-security] 20090123 Re: CVE id request: typo3 SA-2009-001</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1711" source="DEBIAN">DSA-1711</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-001/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-001/</ref>
      <ref url="http://secunia.com/advisories/33679" source="SECUNIA">33679</ref>
      <ref url="http://secunia.com/advisories/33617" source="SECUNIA" adv="1">33617</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="typo3">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.0.7"/>
        <vers num="4.0.8"/>
        <vers num="4.0.9"/>
        <vers num="4.1.0" edition="beta1"/>
        <vers num="4.1.0" edition="rc1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.1.6"/>
        <vers num="4.1.7"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0259" published="2009-01-22" name="CVE-2009-0259" modified="2009-04-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008, as demonstrated by 2008-crash.doc.rar, and a similar issue to CVE-2008-4841.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48213" source="XF">openoffice-wordprocessor-code-execution(48213)</ref>
      <ref url="http://www.securityfocus.com/bid/33383" source="BID">33383</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/21/9" source="MLIST">[oss-security] 20090121 CVE Request -- openoffice.org (CVE-2008-4841)</ref>
      <ref url="http://www.milw0rm.com/exploits/6560" source="MILW0RM">6560</ref>
      <ref url="http://milw0rm.com/sploits/2008-crash.doc.rar" source="MISC">http://milw0rm.com/sploits/2008-crash.doc.rar</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openoffice" name="openoffice.org">
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0260" published="2009-01-23" name="CVE-2009-0260" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin before 1.8.1 allow remote attackers to inject arbitrary web script or HTML via an AttachFile action to the WikiSandBox component with (1) the rename parameter or (2) the drawing parameter (aka the basename variable).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33365" source="BID" patch="1">33365</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48126" source="XF">moinmoin-attachfilepy-xss(48126)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0195" source="VUPEN">ADV-2009-0195</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-716-1" source="UBUNTU">USN-716-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500197/100/0/threaded" source="BUGTRAQ">20090120 MoinMoin Wiki Engine XSS Vulnerability</ref>
      <ref url="http://secunia.com/advisories/33755" source="SECUNIA">33755</ref>
      <ref url="http://secunia.com/advisories/33716" source="SECUNIA">33716</ref>
      <ref url="http://secunia.com/advisories/33593" source="SECUNIA" adv="1">33593</ref>
      <ref url="http://osvdb.org/51485" source="OSVDB">51485</ref>
      <ref url="http://moinmo.in/SecurityFixes#moin1.8.1" source="CONFIRM">http://moinmo.in/SecurityFixes#moin1.8.1</ref>
      <ref url="http://lists.debian.org/debian-security-announce/2009/msg00023.html" source="DEBIAN">DSA-1715</ref>
      <ref url="http://hg.moinmo.in/moin/1.8/rev/8cb4d34ccbc1" source="CONFIRM">http://hg.moinmo.in/moin/1.8/rev/8cb4d34ccbc1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moinmoin" name="moinmoin">
        <vers num="0.1"/>
        <vers num="0.10"/>
        <vers num="0.11"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.7"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.3_rc1"/>
        <vers num="1.5.3_rc2"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.5_rc1"/>
        <vers num="1.5.5a"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="1.6"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.7.0"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="1.7.3"/>
        <vers prev="1" num="1.8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0261" published="2009-01-23" name="CVE-2009-0261" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in EffectMatrix Total Video Player 1.31 allows user-assisted attackers to execute arbitrary code via a Skins\DefaultSkin\DefaultSkin.ini file with a large ColumnHeaderSpan value.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48140" source="XF">totalvideoplayer-defaultskin-bo(48140)</ref>
      <ref url="http://www.securityfocus.com/bid/33373" source="BID">33373</ref>
      <ref url="http://www.milw0rm.com/exploits/7839" source="MILW0RM">7839</ref>
    </refs>
    <vuln_soft>
      <prod vendor="effectmatrix" name="total_video_player">
        <vers num="1.31"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0262" published="2009-01-23" name="CVE-2009-0262" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Triologic Media Player 7 and 8.0.0.0 allows user-assisted remote attackers to execute arbitrary code via a long string in a .m3u playlist file.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0097" source="VUPEN">ADV-2009-0097</ref>
      <ref url="http://www.securityfocus.com/bid/33221" source="BID">33221</ref>
      <ref url="http://secunia.com/advisories/33496" source="SECUNIA">33496</ref>
      <ref url="http://milw0rm.com/exploits/7737" source="MILW0RM">7737</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trilogic" name="media_player">
        <vers num="7"/>
        <vers num="8.0.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0263" published="2009-01-23" name="CVE-2009-0263" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in Winamp 5.541 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a large Common Chunk (COMM) header value in an AIFF file and (2) a large invalid value in an MP3 file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0113" source="VUPEN">ADV-2009-0113</ref>
      <ref url="http://www.securityfocus.com/bid/33226" source="BID">33226</ref>
      <ref url="http://secunia.com/advisories/33478" source="SECUNIA">33478</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14756" source="OVAL">oval:org.mitre.oval:def:14756</ref>
      <ref url="http://milw0rm.com/exploits/7742" source="MILW0RM">7742</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nullsoft" name="winamp">
        <vers num="2.0"/>
        <vers num="2.10"/>
        <vers num="2.24"/>
        <vers num="2.4"/>
        <vers num="2.50"/>
        <vers num="2.5e"/>
        <vers num="2.60" edition=""/>
        <vers num="2.60" edition=":lite"/>
        <vers num="2.60" edition=":full"/>
        <vers num="2.61" edition=""/>
        <vers num="2.61" edition=":full"/>
        <vers num="2.62" edition=""/>
        <vers num="2.62" edition=":standard"/>
        <vers num="2.64" edition=""/>
        <vers num="2.64" edition=":standard"/>
        <vers num="2.65"/>
        <vers num="2.6x"/>
        <vers num="2.70" edition=""/>
        <vers num="2.70" edition=":full"/>
        <vers num="2.71"/>
        <vers num="2.72"/>
        <vers num="2.73" edition=""/>
        <vers num="2.73" edition=":full"/>
        <vers num="2.74"/>
        <vers num="2.75"/>
        <vers num="2.76"/>
        <vers num="2.77"/>
        <vers num="2.78"/>
        <vers num="2.79"/>
        <vers num="2.7x"/>
        <vers num="2.80"/>
        <vers num="2.81"/>
        <vers num="2.90"/>
        <vers num="2.91"/>
        <vers num="2.95"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.01"/>
        <vers num="5.02"/>
        <vers num="5.03"/>
        <vers num="5.03a"/>
        <vers num="5.04"/>
        <vers num="5.05"/>
        <vers num="5.06"/>
        <vers num="5.07"/>
        <vers num="5.08" edition="c"/>
        <vers num="5.08" edition="d"/>
        <vers num="5.08" edition="e"/>
        <vers num="5.08c"/>
        <vers num="5.08d"/>
        <vers num="5.08e"/>
        <vers num="5.09"/>
        <vers num="5.091"/>
        <vers num="5.093"/>
        <vers num="5.094"/>
        <vers num="5.1"/>
        <vers num="5.11"/>
        <vers num="5.111"/>
        <vers num="5.112"/>
        <vers num="5.12"/>
        <vers num="5.13"/>
        <vers num="5.2"/>
        <vers num="5.21"/>
        <vers num="5.22"/>
        <vers num="5.23"/>
        <vers num="5.24"/>
        <vers num="5.3"/>
        <vers num="5.31"/>
        <vers num="5.32"/>
        <vers num="5.33"/>
        <vers num="5.34"/>
        <vers num="5.35"/>
        <vers num="5.36"/>
        <vers num="5.5"/>
        <vers num="5.51"/>
        <vers num="5.52"/>
        <vers num="5.53"/>
        <vers num="5.54"/>
        <vers prev="1" num="5.541"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0264" published="2009-01-26" name="CVE-2009-0264" modified="2009-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the Registry Setting Tool in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.fujitsu.com/global/services/computing/server/primequest/products/os/windows-server-2008-2.html" source="CONFIRM" patch="1" adv="1">http://www.fujitsu.com/global/services/computing/server/primequest/products/os/windows-server-2008-2.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48315" source="XF">systemcast-registrytool-bo(48315)</ref>
      <ref url="http://www.securityfocus.com/bid/33644" source="BID">33644</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fujitsu" name="systemcastwizard_lite">
        <vers num="1.7"/>
        <vers num="1.8"/>
        <vers num="1.8a"/>
        <vers num="1.9"/>
        <vers num="2.0"/>
        <vers prev="1" num="2.0a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0265" published="2009-01-26" name="CVE-2009-0265" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077 and CVE-2009-0025.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://www.isc.org/node/373" source="CONFIRM" adv="1">https://www.isc.org/node/373</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0043" source="VUPEN">ADV-2009-0043</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:037" source="MANDRIVA">MDVSA-2009:037</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.540362" source="SLACKWARE">SSA:2009-014-02</ref>
      <ref url="http://secunia.com/advisories/33559" source="SECUNIA" adv="1">33559</ref>
      <ref url="http://groups.google.com/group/comp.protocols.dns.bind/browse_thread/thread/49ef622c8329fd33" source="MISC">http://groups.google.com/group/comp.protocols.dns.bind/browse_thread/thread/49ef622c8329fd33</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="4"/>
        <vers num="4.9"/>
        <vers num="4.9.10"/>
        <vers num="4.9.2"/>
        <vers num="4.9.3"/>
        <vers num="4.9.4"/>
        <vers num="4.9.5" edition="p1"/>
        <vers num="4.9.6"/>
        <vers num="4.9.7"/>
        <vers num="4.9.8"/>
        <vers num="4.9.9"/>
        <vers num="8"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.1.2"/>
        <vers num="8.2" edition="p1"/>
        <vers num="8.2.1"/>
        <vers num="8.2.2" edition="p1"/>
        <vers num="8.2.2" edition="p2"/>
        <vers num="8.2.2" edition="p3"/>
        <vers num="8.2.2" edition="p4"/>
        <vers num="8.2.2" edition="p5"/>
        <vers num="8.2.2" edition="p6"/>
        <vers num="8.2.2" edition="p7"/>
        <vers num="8.2.3"/>
        <vers num="8.2.3_t1a"/>
        <vers num="8.2.3_t9b"/>
        <vers num="8.2.4"/>
        <vers num="8.2.5"/>
        <vers num="8.2.6"/>
        <vers num="8.2.7"/>
        <vers num="8.3.0"/>
        <vers num="8.3.1"/>
        <vers num="8.3.2"/>
        <vers num="8.3.3"/>
        <vers num="8.3.4"/>
        <vers num="8.3.5"/>
        <vers num="8.3.6"/>
        <vers num="8.4"/>
        <vers num="8.4.1"/>
        <vers num="8.4.4"/>
        <vers num="8.4.5"/>
        <vers num="8.4.7"/>
        <vers num="9.0"/>
        <vers num="9.0.1"/>
        <vers num="9.1"/>
        <vers num="9.1.1"/>
        <vers num="9.1.2"/>
        <vers num="9.1.3"/>
        <vers num="9.2"/>
        <vers num="9.2.0"/>
        <vers num="9.2.1"/>
        <vers num="9.2.2" edition="p3"/>
        <vers num="9.2.3"/>
        <vers num="9.2.4"/>
        <vers num="9.2.5"/>
        <vers num="9.2.6"/>
        <vers num="9.2.7"/>
        <vers num="9.2.9"/>
        <vers num="9.3"/>
        <vers num="9.3.0"/>
        <vers num="9.3.1"/>
        <vers num="9.3.2"/>
        <vers num="9.3.3"/>
        <vers num="9.3.5-p2-w1" edition="windows"/>
        <vers num="9.4"/>
        <vers num="9.4.0" edition="rc1"/>
        <vers num="9.4.0a1"/>
        <vers num="9.4.0a2"/>
        <vers num="9.4.0a3"/>
        <vers num="9.4.0a4"/>
        <vers num="9.4.0a5"/>
        <vers num="9.4.0a6"/>
        <vers num="9.4.0b1"/>
        <vers num="9.4.0b2"/>
        <vers num="9.4.0b3"/>
        <vers num="9.4.0b4"/>
        <vers num="9.4.1"/>
        <vers num="9.4.2"/>
        <vers num="9.4.3" edition="rc1"/>
        <vers num="9.4.3b1"/>
        <vers num="9.4.3b2"/>
        <vers num="9.4.3b3"/>
        <vers num="9.5.0" edition="rc1"/>
        <vers num="9.5.0-p1"/>
        <vers num="9.5.0-p2"/>
        <vers num="9.5.0-p2-w1"/>
        <vers num="9.5.0-p2-w2"/>
        <vers num="9.5.0a5"/>
        <vers num="9.5.0a6"/>
        <vers num="9.5.0a7"/>
        <vers num="9.5.0b1"/>
        <vers num="9.5.0b2"/>
        <vers num="9.5.0b3"/>
        <vers num="9.5.1" edition="rc1"/>
        <vers num="9.5.1" edition="rc2"/>
        <vers num="9.5.1b1"/>
        <vers num="9.5.1b2"/>
        <vers num="9.5.1b3"/>
        <vers prev="1" num="9.6.0" edition="p1"/>
        <vers prev="1" num="9.6.0" edition="rc1"/>
        <vers prev="1" num="9.6.0" edition="rc2"/>
        <vers num="9.6.0a1"/>
        <vers num="9.6.0b1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0266" published="2009-01-26" name="CVE-2009-0266" modified="2009-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Triologic Media Player 8.0.0.0 allows user-assisted remote attackers to execute arbitrary code via a long string in a .m3l playlist file.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/33496" source="SECUNIA" adv="1">33496</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trilogic" name="media_player">
        <vers num="8.0.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0267" published="2009-01-26" name="CVE-2009-0267" modified="2009-03-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">libike in Sun Solaris 9 and 10, and OpenSolaris before snv_100, does not properly check packets, which allows remote attackers to cause a denial of service (in.iked daemon crash) via an unspecified IKE packet, a different vulnerability than CVE-2007-2989.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33407" source="BID" patch="1">33407</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-247406-1" source="SUNALERT" patch="1" adv="1">247406</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-113451-15-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-113451-15-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48178" source="XF">sun-solaris-libike-dos(48178)</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-032.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-032.htm</ref>
      <ref url="http://secunia.com/advisories/33702" source="SECUNIA">33702</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6116" source="OVAL">oval:org.mitre.oval:def:6116</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_01" edition=""/>
        <vers num="snv_01" edition=":sparc"/>
        <vers num="snv_01" edition=":x86"/>
        <vers num="snv_02" edition=""/>
        <vers num="snv_02" edition=":sparc"/>
        <vers num="snv_02" edition=":x86"/>
        <vers num="snv_03" edition=""/>
        <vers num="snv_03" edition=":x86"/>
        <vers num="snv_03" edition=":sparc"/>
        <vers num="snv_04" edition=""/>
        <vers num="snv_04" edition=":x86"/>
        <vers num="snv_04" edition=":sparc"/>
        <vers num="snv_05" edition=""/>
        <vers num="snv_05" edition=":sparc"/>
        <vers num="snv_05" edition=":x86"/>
        <vers num="snv_06" edition=""/>
        <vers num="snv_06" edition=":sparc"/>
        <vers num="snv_06" edition=":x86"/>
        <vers num="snv_07" edition=""/>
        <vers num="snv_07" edition=":sparc"/>
        <vers num="snv_07" edition=":x86"/>
        <vers num="snv_08" edition=""/>
        <vers num="snv_08" edition=":x86"/>
        <vers num="snv_08" edition=":sparc"/>
        <vers num="snv_09" edition=""/>
        <vers num="snv_09" edition=":sparc"/>
        <vers num="snv_09" edition=":x86"/>
        <vers num="snv_10" edition=""/>
        <vers num="snv_10" edition=":x86"/>
        <vers num="snv_10" edition=":sparc"/>
        <vers num="snv_11" edition=""/>
        <vers num="snv_11" edition=":sparc"/>
        <vers num="snv_12" edition=""/>
        <vers num="snv_12" edition=":sparc"/>
        <vers num="snv_13" edition=""/>
        <vers num="snv_13" edition=":sparc"/>
        <vers num="snv_14" edition=""/>
        <vers num="snv_14" edition=":sparc"/>
        <vers num="snv_15" edition=""/>
        <vers num="snv_15" edition=":sparc"/>
        <vers num="snv_16" edition=""/>
        <vers num="snv_16" edition=":sparc"/>
        <vers num="snv_17" edition=""/>
        <vers num="snv_17" edition=":sparc"/>
        <vers num="snv_18" edition=""/>
        <vers num="snv_18" edition=":sparc"/>
        <vers num="snv_19" edition=""/>
        <vers num="snv_19" edition=":sparc"/>
        <vers num="snv_20" edition=""/>
        <vers num="snv_20" edition=":sparc"/>
        <vers num="snv_21" edition=""/>
        <vers num="snv_21" edition=":x86"/>
        <vers num="snv_21" edition=":sparc"/>
        <vers num="snv_22" edition=""/>
        <vers num="snv_22" edition=":sparc"/>
        <vers num="snv_22" edition=":x86"/>
        <vers num="snv_23" edition=""/>
        <vers num="snv_23" edition=":sparc"/>
        <vers num="snv_23" edition=":x86"/>
        <vers num="snv_24" edition=""/>
        <vers num="snv_24" edition=":sparc"/>
        <vers num="snv_24" edition=":x86"/>
        <vers num="snv_25" edition=""/>
        <vers num="snv_25" edition=":sparc"/>
        <vers num="snv_25" edition=":x86"/>
        <vers num="snv_26" edition=""/>
        <vers num="snv_26" edition=":sparc"/>
        <vers num="snv_26" edition=":x86"/>
        <vers num="snv_27" edition=""/>
        <vers num="snv_27" edition=":sparc"/>
        <vers num="snv_27" edition=":x86"/>
        <vers num="snv_28" edition=""/>
        <vers num="snv_28" edition=":sparc"/>
        <vers num="snv_28" edition=":x86"/>
        <vers num="snv_29" edition=""/>
        <vers num="snv_29" edition=":x86"/>
        <vers num="snv_29" edition=":sparc"/>
        <vers num="snv_30" edition=""/>
        <vers num="snv_30" edition=":sparc"/>
        <vers num="snv_30" edition=":x86"/>
        <vers num="snv_31" edition=""/>
        <vers num="snv_31" edition=":sparc"/>
        <vers num="snv_31" edition=":x86"/>
        <vers num="snv_32" edition=""/>
        <vers num="snv_32" edition=":x86"/>
        <vers num="snv_32" edition=":sparc"/>
        <vers num="snv_33" edition=""/>
        <vers num="snv_33" edition=":x86"/>
        <vers num="snv_33" edition=":sparc"/>
        <vers num="snv_34" edition=""/>
        <vers num="snv_34" edition=":sparc"/>
        <vers num="snv_34" edition=":x86"/>
        <vers num="snv_35" edition=""/>
        <vers num="snv_35" edition=":sparc"/>
        <vers num="snv_35" edition=":x86"/>
        <vers num="snv_36" edition=""/>
        <vers num="snv_36" edition=":sparc"/>
        <vers num="snv_36" edition=":x86"/>
        <vers num="snv_37" edition=""/>
        <vers num="snv_37" edition=":sparc"/>
        <vers num="snv_37" edition=":x86"/>
        <vers num="snv_38" edition=""/>
        <vers num="snv_38" edition=":sparc"/>
        <vers num="snv_38" edition=":x86"/>
        <vers num="snv_39" edition=""/>
        <vers num="snv_39" edition=":sparc"/>
        <vers num="snv_39" edition=":x86"/>
        <vers num="snv_40" edition=""/>
        <vers num="snv_40" edition=":x86"/>
        <vers num="snv_40" edition=":sparc"/>
        <vers num="snv_41" edition=""/>
        <vers num="snv_41" edition=":sparc"/>
        <vers num="snv_41" edition=":x86"/>
        <vers num="snv_42" edition=""/>
        <vers num="snv_42" edition=":x86"/>
        <vers num="snv_42" edition=":sparc"/>
        <vers num="snv_43" edition=""/>
        <vers num="snv_43" edition=":sparc"/>
        <vers num="snv_43" edition=":x86"/>
        <vers num="snv_44" edition=""/>
        <vers num="snv_44" edition=":x86"/>
        <vers num="snv_44" edition=":sparc"/>
        <vers num="snv_45" edition=""/>
        <vers num="snv_45" edition=":x86"/>
        <vers num="snv_45" edition=":sparc"/>
        <vers num="snv_46" edition=""/>
        <vers num="snv_46" edition=":sparc"/>
        <vers num="snv_46" edition=":x86"/>
        <vers num="snv_47" edition=""/>
        <vers num="snv_47" edition=":x86"/>
        <vers num="snv_47" edition=":sparc"/>
        <vers num="snv_48" edition=""/>
        <vers num="snv_48" edition=":sparc"/>
        <vers num="snv_48" edition=":x86"/>
        <vers num="snv_49" edition=""/>
        <vers num="snv_49" edition=":sparc"/>
        <vers num="snv_49" edition=":x86"/>
        <vers num="snv_50" edition=""/>
        <vers num="snv_50" edition=":sparc"/>
        <vers num="snv_50" edition=":x86"/>
        <vers num="snv_51" edition=""/>
        <vers num="snv_51" edition=":x86"/>
        <vers num="snv_51" edition=":sparc"/>
        <vers num="snv_52" edition=""/>
        <vers num="snv_52" edition=":x86"/>
        <vers num="snv_52" edition=":sparc"/>
        <vers num="snv_53" edition=""/>
        <vers num="snv_53" edition=":sparc"/>
        <vers num="snv_53" edition=":x86"/>
        <vers num="snv_54" edition=""/>
        <vers num="snv_54" edition=":sparc"/>
        <vers num="snv_54" edition=":x86"/>
        <vers num="snv_55" edition=""/>
        <vers num="snv_55" edition=":sparc"/>
        <vers num="snv_55" edition=":x86"/>
        <vers num="snv_56" edition=""/>
        <vers num="snv_56" edition=":x86"/>
        <vers num="snv_56" edition=":sparc"/>
        <vers num="snv_57" edition=""/>
        <vers num="snv_57" edition=":x86"/>
        <vers num="snv_57" edition=":sparc"/>
        <vers num="snv_58" edition=""/>
        <vers num="snv_58" edition=":sparc"/>
        <vers num="snv_58" edition=":x86"/>
        <vers num="snv_59" edition=""/>
        <vers num="snv_59" edition=":sparc"/>
        <vers num="snv_59" edition=":x86"/>
        <vers num="snv_60" edition=""/>
        <vers num="snv_60" edition=":x86"/>
        <vers num="snv_60" edition=":sparc"/>
        <vers num="snv_61" edition=""/>
        <vers num="snv_61" edition=":sparc"/>
        <vers num="snv_61" edition=":x86"/>
        <vers num="snv_62" edition=""/>
        <vers num="snv_62" edition=":x86"/>
        <vers num="snv_62" edition=":sparc"/>
        <vers num="snv_63" edition=""/>
        <vers num="snv_63" edition=":x86"/>
        <vers num="snv_63" edition=":sparc"/>
        <vers num="snv_64" edition=""/>
        <vers num="snv_64" edition=":x86"/>
        <vers num="snv_64" edition=":sparc"/>
        <vers num="snv_65" edition=""/>
        <vers num="snv_65" edition=":sparc"/>
        <vers num="snv_65" edition=":x86"/>
        <vers num="snv_66" edition=""/>
        <vers num="snv_66" edition=":x86"/>
        <vers num="snv_66" edition=":sparc"/>
        <vers num="snv_67" edition=""/>
        <vers num="snv_67" edition=":sparc"/>
        <vers num="snv_67" edition=":x86"/>
        <vers num="snv_68" edition=""/>
        <vers num="snv_68" edition=":x86"/>
        <vers num="snv_68" edition=":sparc"/>
        <vers num="snv_69" edition=""/>
        <vers num="snv_69" edition=":sparc"/>
        <vers num="snv_69" edition=":x86"/>
        <vers num="snv_70" edition=""/>
        <vers num="snv_70" edition=":sparc"/>
        <vers num="snv_70" edition=":x86"/>
        <vers num="snv_71" edition=""/>
        <vers num="snv_71" edition=":sparc"/>
        <vers num="snv_71" edition=":x86"/>
        <vers num="snv_72" edition=""/>
        <vers num="snv_72" edition=":x86"/>
        <vers num="snv_72" edition=":sparc"/>
        <vers num="snv_73" edition=""/>
        <vers num="snv_73" edition=":x86"/>
        <vers num="snv_73" edition=":sparc"/>
        <vers num="snv_74" edition=""/>
        <vers num="snv_74" edition=":x86"/>
        <vers num="snv_74" edition=":sparc"/>
        <vers num="snv_75" edition=""/>
        <vers num="snv_75" edition=":x86"/>
        <vers num="snv_75" edition=":sparc"/>
        <vers num="snv_76" edition=""/>
        <vers num="snv_76" edition=":sparc"/>
        <vers num="snv_76" edition=":x86"/>
        <vers num="snv_77" edition=""/>
        <vers num="snv_77" edition=":sparc"/>
        <vers num="snv_77" edition=":x86"/>
        <vers num="snv_78" edition=""/>
        <vers num="snv_78" edition=":sparc"/>
        <vers num="snv_78" edition=":x86"/>
        <vers num="snv_79" edition=""/>
        <vers num="snv_79" edition=":x86"/>
        <vers num="snv_79" edition=":sparc"/>
        <vers num="snv_80" edition=""/>
        <vers num="snv_80" edition=":x86"/>
        <vers num="snv_80" edition=":sparc"/>
        <vers num="snv_81" edition=""/>
        <vers num="snv_81" edition=":x86"/>
        <vers num="snv_81" edition=":sparc"/>
        <vers num="snv_82" edition=""/>
        <vers num="snv_82" edition=":x86"/>
        <vers num="snv_82" edition=":sparc"/>
        <vers num="snv_83" edition=""/>
        <vers num="snv_83" edition=":sparc"/>
        <vers num="snv_83" edition=":x86"/>
        <vers num="snv_84" edition=""/>
        <vers num="snv_84" edition=":x86"/>
        <vers num="snv_84" edition=":sparc"/>
        <vers num="snv_85" edition=""/>
        <vers num="snv_85" edition=":sparc"/>
        <vers num="snv_85" edition=":x86"/>
        <vers num="snv_86" edition=""/>
        <vers num="snv_86" edition=":sparc"/>
        <vers num="snv_86" edition=":x86"/>
        <vers num="snv_87" edition=""/>
        <vers num="snv_87" edition=":sparc"/>
        <vers num="snv_87" edition=":x86"/>
        <vers num="snv_88" edition=""/>
        <vers num="snv_88" edition=":x86"/>
        <vers num="snv_88" edition=":sparc"/>
        <vers num="snv_89" edition=""/>
        <vers num="snv_89" edition=":x86"/>
        <vers num="snv_89" edition=":sparc"/>
        <vers num="snv_90" edition=""/>
        <vers num="snv_90" edition=":sparc"/>
        <vers num="snv_90" edition=":x86"/>
        <vers num="snv_91" edition=""/>
        <vers num="snv_91" edition=":x86"/>
        <vers num="snv_91" edition=":sparc"/>
        <vers num="snv_92" edition=""/>
        <vers num="snv_92" edition=":x86"/>
        <vers num="snv_92" edition=":sparc"/>
        <vers num="snv_93" edition=""/>
        <vers num="snv_93" edition=":sparc"/>
        <vers num="snv_93" edition=":x86"/>
        <vers num="snv_94" edition=""/>
        <vers num="snv_94" edition=":x86"/>
        <vers num="snv_94" edition=":sparc"/>
        <vers num="snv_95" edition=""/>
        <vers num="snv_95" edition=":x86"/>
        <vers num="snv_95" edition=":sparc"/>
        <vers num="snv_96" edition=""/>
        <vers num="snv_96" edition=":sparc"/>
        <vers num="snv_96" edition=":x86"/>
        <vers num="snv_97" edition=""/>
        <vers num="snv_97" edition=":x86"/>
        <vers num="snv_97" edition=":sparc"/>
        <vers num="snv_98" edition=""/>
        <vers num="snv_98" edition=":x86"/>
        <vers num="snv_98" edition=":sparc"/>
        <vers prev="1" num="snv_99" edition=""/>
        <vers prev="1" num="snv_99" edition=":sparc"/>
        <vers prev="1" num="snv_99" edition=":x86"/>
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10" edition=""/>
        <vers num="10" edition=":sparc"/>
        <vers num="10" edition=":x86"/>
        <vers num="9" edition=""/>
        <vers num="9" edition=":sparc"/>
        <vers num="9" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0268" published="2009-01-26" name="CVE-2009-0268" modified="2009-03-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Race condition in the pseudo-terminal (aka pty) driver module in Sun Solaris 8 through 10, and OpenSolaris before snv_103, allows local users to cause a denial of service (panic) via unspecified vectors related to lack of "properly sequenced code" in ptc and ptsl.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33406" source="BID" patch="1">33406</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-249586-1" source="SUNALERT" patch="1" adv="1">249586</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-113685-07-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-113685-07-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48179" source="XF">solaris-pseudo-terminal-dos(48179)</ref>
      <ref url="http://www.securitytracker.com/id?1021640" source="SECTRACK">1021640</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-034.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-034.htm</ref>
      <ref url="http://secunia.com/advisories/33708" source="SECUNIA">33708</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6061" source="OVAL">oval:org.mitre.oval:def:6061</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_01" edition=""/>
        <vers num="snv_01" edition=":sparc"/>
        <vers num="snv_01" edition=":x86"/>
        <vers num="snv_02" edition=""/>
        <vers num="snv_02" edition=":sparc"/>
        <vers num="snv_02" edition=":x86"/>
        <vers num="snv_03" edition=""/>
        <vers num="snv_03" edition=":x86"/>
        <vers num="snv_03" edition=":sparc"/>
        <vers num="snv_04" edition=""/>
        <vers num="snv_04" edition=":x86"/>
        <vers num="snv_04" edition=":sparc"/>
        <vers num="snv_05" edition=""/>
        <vers num="snv_05" edition=":sparc"/>
        <vers num="snv_05" edition=":x86"/>
        <vers num="snv_06" edition=""/>
        <vers num="snv_06" edition=":sparc"/>
        <vers num="snv_06" edition=":x86"/>
        <vers num="snv_07" edition=""/>
        <vers num="snv_07" edition=":sparc"/>
        <vers num="snv_07" edition=":x86"/>
        <vers num="snv_08" edition=""/>
        <vers num="snv_08" edition=":x86"/>
        <vers num="snv_08" edition=":sparc"/>
        <vers num="snv_09" edition=""/>
        <vers num="snv_09" edition=":x86"/>
        <vers num="snv_09" edition=":sparc"/>
        <vers num="snv_10" edition=""/>
        <vers num="snv_10" edition=":x86"/>
        <vers num="snv_10" edition=":sparc"/>
        <vers num="snv_100" edition=""/>
        <vers num="snv_100" edition=":sparc"/>
        <vers num="snv_100" edition=":x86"/>
        <vers num="snv_101" edition=""/>
        <vers num="snv_101" edition=":x86"/>
        <vers num="snv_101" edition=":sparc"/>
        <vers prev="1" num="snv_102" edition=""/>
        <vers prev="1" num="snv_102" edition=":sparc"/>
        <vers prev="1" num="snv_102" edition=":x86"/>
        <vers num="snv_11" edition=""/>
        <vers num="snv_11" edition=":x86"/>
        <vers num="snv_11" edition=":sparc"/>
        <vers num="snv_12" edition=""/>
        <vers num="snv_12" edition=":x86"/>
        <vers num="snv_12" edition=":sparc"/>
        <vers num="snv_13" edition=""/>
        <vers num="snv_13" edition=":x86"/>
        <vers num="snv_13" edition=":sparc"/>
        <vers num="snv_14" edition=""/>
        <vers num="snv_14" edition=":sparc"/>
        <vers num="snv_14" edition=":x86"/>
        <vers num="snv_15" edition=""/>
        <vers num="snv_15" edition=":x86"/>
        <vers num="snv_15" edition=":sparc"/>
        <vers num="snv_16" edition=""/>
        <vers num="snv_16" edition=":sparc"/>
        <vers num="snv_16" edition=":x86"/>
        <vers num="snv_17" edition=""/>
        <vers num="snv_17" edition=":x86"/>
        <vers num="snv_17" edition=":sparc"/>
        <vers num="snv_18" edition=""/>
        <vers num="snv_18" edition=":x86"/>
        <vers num="snv_18" edition=":sparc"/>
        <vers num="snv_19" edition=""/>
        <vers num="snv_19" edition=":sparc"/>
        <vers num="snv_19" edition=":x86"/>
        <vers num="snv_20" edition=""/>
        <vers num="snv_20" edition=":x86"/>
        <vers num="snv_20" edition=":sparc"/>
        <vers num="snv_21" edition=""/>
        <vers num="snv_21" edition=":sparc"/>
        <vers num="snv_21" edition=":x86"/>
        <vers num="snv_22" edition=""/>
        <vers num="snv_22" edition=":sparc"/>
        <vers num="snv_22" edition=":x86"/>
        <vers num="snv_23" edition=""/>
        <vers num="snv_23" edition=":sparc"/>
        <vers num="snv_23" edition=":x86"/>
        <vers num="snv_24" edition=""/>
        <vers num="snv_24" edition=":sparc"/>
        <vers num="snv_24" edition=":x86"/>
        <vers num="snv_25" edition=""/>
        <vers num="snv_25" edition=":x86"/>
        <vers num="snv_25" edition=":sparc"/>
        <vers num="snv_26" edition=""/>
        <vers num="snv_26" edition=":x86"/>
        <vers num="snv_26" edition=":sparc"/>
        <vers num="snv_27" edition=""/>
        <vers num="snv_27" edition=":sparc"/>
        <vers num="snv_27" edition=":x86"/>
        <vers num="snv_28" edition=""/>
        <vers num="snv_28" edition=":x86"/>
        <vers num="snv_28" edition=":sparc"/>
        <vers num="snv_29" edition=""/>
        <vers num="snv_29" edition=":x86"/>
        <vers num="snv_29" edition=":sparc"/>
        <vers num="snv_30" edition=""/>
        <vers num="snv_30" edition=":sparc"/>
        <vers num="snv_30" edition=":x86"/>
        <vers num="snv_31" edition=""/>
        <vers num="snv_31" edition=":sparc"/>
        <vers num="snv_31" edition=":x86"/>
        <vers num="snv_32" edition=""/>
        <vers num="snv_32" edition=":x86"/>
        <vers num="snv_32" edition=":sparc"/>
        <vers num="snv_33" edition=""/>
        <vers num="snv_33" edition=":x86"/>
        <vers num="snv_33" edition=":sparc"/>
        <vers num="snv_34" edition=""/>
        <vers num="snv_34" edition=":sparc"/>
        <vers num="snv_34" edition=":x86"/>
        <vers num="snv_35" edition=""/>
        <vers num="snv_35" edition=":sparc"/>
        <vers num="snv_35" edition=":x86"/>
        <vers num="snv_36" edition=""/>
        <vers num="snv_36" edition=":x86"/>
        <vers num="snv_36" edition=":sparc"/>
        <vers num="snv_37" edition=""/>
        <vers num="snv_37" edition=":sparc"/>
        <vers num="snv_37" edition=":x86"/>
        <vers num="snv_38" edition=""/>
        <vers num="snv_38" edition=":sparc"/>
        <vers num="snv_38" edition=":x86"/>
        <vers num="snv_39" edition=""/>
        <vers num="snv_39" edition=":sparc"/>
        <vers num="snv_39" edition=":x86"/>
        <vers num="snv_40" edition=""/>
        <vers num="snv_40" edition=":sparc"/>
        <vers num="snv_40" edition=":x86"/>
        <vers num="snv_41" edition=""/>
        <vers num="snv_41" edition=":sparc"/>
        <vers num="snv_41" edition=":x86"/>
        <vers num="snv_42" edition=""/>
        <vers num="snv_42" edition=":x86"/>
        <vers num="snv_42" edition=":sparc"/>
        <vers num="snv_43" edition=""/>
        <vers num="snv_43" edition=":sparc"/>
        <vers num="snv_43" edition=":x86"/>
        <vers num="snv_44" edition=""/>
        <vers num="snv_44" edition=":x86"/>
        <vers num="snv_44" edition=":sparc"/>
        <vers num="snv_45" edition=""/>
        <vers num="snv_45" edition=":x86"/>
        <vers num="snv_45" edition=":sparc"/>
        <vers num="snv_46" edition=""/>
        <vers num="snv_46" edition=":x86"/>
        <vers num="snv_46" edition=":sparc"/>
        <vers num="snv_47" edition=""/>
        <vers num="snv_47" edition=":x86"/>
        <vers num="snv_47" edition=":sparc"/>
        <vers num="snv_48" edition=""/>
        <vers num="snv_48" edition=":sparc"/>
        <vers num="snv_48" edition=":x86"/>
        <vers num="snv_49" edition=""/>
        <vers num="snv_49" edition=":sparc"/>
        <vers num="snv_49" edition=":x86"/>
        <vers num="snv_50" edition=""/>
        <vers num="snv_50" edition=":sparc"/>
        <vers num="snv_50" edition=":x86"/>
        <vers num="snv_51" edition=""/>
        <vers num="snv_51" edition=":sparc"/>
        <vers num="snv_51" edition=":x86"/>
        <vers num="snv_52" edition=""/>
        <vers num="snv_52" edition=":sparc"/>
        <vers num="snv_52" edition=":x86"/>
        <vers num="snv_53" edition=""/>
        <vers num="snv_53" edition=":sparc"/>
        <vers num="snv_53" edition=":x86"/>
        <vers num="snv_54" edition=""/>
        <vers num="snv_54" edition=":x86"/>
        <vers num="snv_54" edition=":sparc"/>
        <vers num="snv_55" edition=""/>
        <vers num="snv_55" edition=":sparc"/>
        <vers num="snv_55" edition=":x86"/>
        <vers num="snv_56" edition=""/>
        <vers num="snv_56" edition=":x86"/>
        <vers num="snv_56" edition=":sparc"/>
        <vers num="snv_57" edition=""/>
        <vers num="snv_57" edition=":x86"/>
        <vers num="snv_57" edition=":sparc"/>
        <vers num="snv_58" edition=""/>
        <vers num="snv_58" edition=":sparc"/>
        <vers num="snv_58" edition=":x86"/>
        <vers num="snv_59" edition=""/>
        <vers num="snv_59" edition=":sparc"/>
        <vers num="snv_59" edition=":x86"/>
        <vers num="snv_60" edition=""/>
        <vers num="snv_60" edition=":x86"/>
        <vers num="snv_60" edition=":sparc"/>
        <vers num="snv_61" edition=""/>
        <vers num="snv_61" edition=":sparc"/>
        <vers num="snv_61" edition=":x86"/>
        <vers num="snv_62" edition=""/>
        <vers num="snv_62" edition=":x86"/>
        <vers num="snv_62" edition=":sparc"/>
        <vers num="snv_63" edition=""/>
        <vers num="snv_63" edition=":sparc"/>
        <vers num="snv_63" edition=":x86"/>
        <vers num="snv_64" edition=""/>
        <vers num="snv_64" edition=":x86"/>
        <vers num="snv_64" edition=":sparc"/>
        <vers num="snv_65" edition=""/>
        <vers num="snv_65" edition=":x86"/>
        <vers num="snv_65" edition=":sparc"/>
        <vers num="snv_66" edition=""/>
        <vers num="snv_66" edition=":x86"/>
        <vers num="snv_66" edition=":sparc"/>
        <vers num="snv_67" edition=""/>
        <vers num="snv_67" edition=":sparc"/>
        <vers num="snv_67" edition=":x86"/>
        <vers num="snv_68" edition=""/>
        <vers num="snv_68" edition=":x86"/>
        <vers num="snv_68" edition=":sparc"/>
        <vers num="snv_69" edition=""/>
        <vers num="snv_69" edition=":sparc"/>
        <vers num="snv_69" edition=":x86"/>
        <vers num="snv_70" edition=""/>
        <vers num="snv_70" edition=":sparc"/>
        <vers num="snv_70" edition=":x86"/>
        <vers num="snv_71" edition=""/>
        <vers num="snv_71" edition=":x86"/>
        <vers num="snv_71" edition=":sparc"/>
        <vers num="snv_72" edition=""/>
        <vers num="snv_72" edition=":x86"/>
        <vers num="snv_72" edition=":sparc"/>
        <vers num="snv_73" edition=""/>
        <vers num="snv_73" edition=":x86"/>
        <vers num="snv_73" edition=":sparc"/>
        <vers num="snv_74" edition=""/>
        <vers num="snv_74" edition=":sparc"/>
        <vers num="snv_74" edition=":x86"/>
        <vers num="snv_75" edition=""/>
        <vers num="snv_75" edition=":sparc"/>
        <vers num="snv_75" edition=":x86"/>
        <vers num="snv_76" edition=""/>
        <vers num="snv_76" edition=":x86"/>
        <vers num="snv_76" edition=":sparc"/>
        <vers num="snv_77" edition=""/>
        <vers num="snv_77" edition=":sparc"/>
        <vers num="snv_77" edition=":x86"/>
        <vers num="snv_78" edition=""/>
        <vers num="snv_78" edition=":sparc"/>
        <vers num="snv_78" edition=":x86"/>
        <vers num="snv_79" edition=""/>
        <vers num="snv_79" edition=":x86"/>
        <vers num="snv_79" edition=":sparc"/>
        <vers num="snv_80" edition=""/>
        <vers num="snv_80" edition=":x86"/>
        <vers num="snv_80" edition=":sparc"/>
        <vers num="snv_81" edition=""/>
        <vers num="snv_81" edition=":x86"/>
        <vers num="snv_81" edition=":sparc"/>
        <vers num="snv_82" edition=""/>
        <vers num="snv_82" edition=":x86"/>
        <vers num="snv_82" edition=":sparc"/>
        <vers num="snv_83" edition=""/>
        <vers num="snv_83" edition=":x86"/>
        <vers num="snv_83" edition=":sparc"/>
        <vers num="snv_84" edition=""/>
        <vers num="snv_84" edition=":x86"/>
        <vers num="snv_84" edition=":sparc"/>
        <vers num="snv_85" edition=""/>
        <vers num="snv_85" edition=":x86"/>
        <vers num="snv_85" edition=":sparc"/>
        <vers num="snv_86" edition=""/>
        <vers num="snv_86" edition=":sparc"/>
        <vers num="snv_86" edition=":x86"/>
        <vers num="snv_87" edition=""/>
        <vers num="snv_87" edition=":sparc"/>
        <vers num="snv_87" edition=":x86"/>
        <vers num="snv_88" edition=""/>
        <vers num="snv_88" edition=":x86"/>
        <vers num="snv_88" edition=":sparc"/>
        <vers num="snv_89" edition=""/>
        <vers num="snv_89" edition=":x86"/>
        <vers num="snv_89" edition=":sparc"/>
        <vers num="snv_90" edition=""/>
        <vers num="snv_90" edition=":sparc"/>
        <vers num="snv_90" edition=":x86"/>
        <vers num="snv_91" edition=""/>
        <vers num="snv_91" edition=":sparc"/>
        <vers num="snv_91" edition=":x86"/>
        <vers num="snv_92" edition=""/>
        <vers num="snv_92" edition=":sparc"/>
        <vers num="snv_92" edition=":x86"/>
        <vers num="snv_93" edition=""/>
        <vers num="snv_93" edition=":sparc"/>
        <vers num="snv_93" edition=":x86"/>
        <vers num="snv_94" edition=""/>
        <vers num="snv_94" edition=":x86"/>
        <vers num="snv_94" edition=":sparc"/>
        <vers num="snv_95" edition=""/>
        <vers num="snv_95" edition=":x86"/>
        <vers num="snv_95" edition=":sparc"/>
        <vers num="snv_96" edition=""/>
        <vers num="snv_96" edition=":sparc"/>
        <vers num="snv_96" edition=":x86"/>
        <vers num="snv_97" edition=""/>
        <vers num="snv_97" edition=":x86"/>
        <vers num="snv_97" edition=":sparc"/>
        <vers num="snv_98" edition=""/>
        <vers num="snv_98" edition=":sparc"/>
        <vers num="snv_98" edition=":x86"/>
        <vers num="snv_99" edition=""/>
        <vers num="snv_99" edition=":sparc"/>
        <vers num="snv_99" edition=":x86"/>
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10" edition=""/>
        <vers num="10" edition=":sparc"/>
        <vers num="10" edition=":x86"/>
        <vers num="8" edition=""/>
        <vers num="8" edition=":sparc"/>
        <vers num="8" edition=":x86"/>
        <vers num="9" edition=""/>
        <vers num="9" edition=":x86"/>
        <vers num="9" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0269" published="2009-01-26" name="CVE-2009-0269" modified="2012-03-19" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">fs/ecryptfs/inode.c in the eCryptfs subsystem in the Linux kernel before 2.6.28.1 allows local users to cause a denial of service (fault or memory corruption), or possibly have unspecified other impact, via a readlink call that results in an error, leading to use of a -1 return value as an array index.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33412" source="BID" patch="1">33412</ref>
      <ref url="https://lists.launchpad.net/ecryptfs-devel/msg00011.html" source="MLIST">[ecryptfs-devel] 20081222 Re: [PATCH, v5] eCryptfs: check readlink result was not an error before using it</ref>
      <ref url="https://lists.launchpad.net/ecryptfs-devel/msg00010.html" source="MLIST">[ecryptfs-devel] 20081222 Re: [PATCH, v5] eCryptfs: check readlink result was not an error before using it</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48188" source="XF">linux-kernel-readlink-bo(48188)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-751-1" source="UBUNTU">USN-751-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0360.html" source="REDHAT">RHSA-2009:0360</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0326.html" source="REDHAT">RHSA-2009:0326</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:118" source="MANDRIVA">MDVSA-2009:118</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.1" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.1</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1787" source="DEBIAN">DSA-1787</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1749" source="DEBIAN">DSA-1749</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA">37471</ref>
      <ref url="http://secunia.com/advisories/35394" source="SECUNIA">35394</ref>
      <ref url="http://secunia.com/advisories/35390" source="SECUNIA">35390</ref>
      <ref url="http://secunia.com/advisories/34981" source="SECUNIA">34981</ref>
      <ref url="http://secunia.com/advisories/34502" source="SECUNIA">34502</ref>
      <ref url="http://secunia.com/advisories/34394" source="SECUNIA">34394</ref>
      <ref url="http://secunia.com/advisories/33758" source="SECUNIA">33758</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8944" source="OVAL">oval:org.mitre.oval:def:8944</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8169" source="OVAL">oval:org.mitre.oval:def:8169</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE">SUSE-SA:2009:031</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE">SUSE-SA:2009:030</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.html" source="SUSE">SUSE-SA:2009:010</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git;a=commit;h=a17d5232de7b53d34229de79ec22f4bb04adb7e4" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git;a=commit;h=a17d5232de7b53d34229de79ec22f4bb04adb7e4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.2.27"/>
        <vers num="2.4.36"/>
        <vers num="2.4.36.1"/>
        <vers num="2.4.36.2"/>
        <vers num="2.4.36.3"/>
        <vers num="2.4.36.4"/>
        <vers num="2.4.36.5"/>
        <vers num="2.4.36.6"/>
        <vers num="2.6"/>
        <vers num="2.6.18" edition="rc1"/>
        <vers num="2.6.18" edition="rc2"/>
        <vers num="2.6.18" edition="rc3"/>
        <vers num="2.6.18" edition="rc4"/>
        <vers num="2.6.18" edition="rc5"/>
        <vers num="2.6.18" edition="rc6"/>
        <vers num="2.6.18" edition="rc7"/>
        <vers num="2.6.19.4"/>
        <vers num="2.6.19.5"/>
        <vers num="2.6.19.6"/>
        <vers num="2.6.19.7"/>
        <vers num="2.6.20.16"/>
        <vers num="2.6.20.17"/>
        <vers num="2.6.20.18"/>
        <vers num="2.6.20.19"/>
        <vers num="2.6.20.20"/>
        <vers num="2.6.20.21"/>
        <vers num="2.6.21.5"/>
        <vers num="2.6.21.6"/>
        <vers num="2.6.21.7"/>
        <vers num="2.6.22"/>
        <vers num="2.6.22.1"/>
        <vers num="2.6.22.10"/>
        <vers num="2.6.22.11"/>
        <vers num="2.6.22.12"/>
        <vers num="2.6.22.13"/>
        <vers num="2.6.22.14"/>
        <vers num="2.6.22.15"/>
        <vers num="2.6.22.17"/>
        <vers num="2.6.22.18"/>
        <vers num="2.6.22.19"/>
        <vers num="2.6.22.2"/>
        <vers num="2.6.22.20"/>
        <vers num="2.6.22.21"/>
        <vers num="2.6.22.22"/>
        <vers num="2.6.22.8"/>
        <vers num="2.6.22.9"/>
        <vers num="2.6.22_rc1"/>
        <vers num="2.6.22_rc7"/>
        <vers num="2.6.23"/>
        <vers num="2.6.23.10"/>
        <vers num="2.6.23.11"/>
        <vers num="2.6.23.12"/>
        <vers num="2.6.23.13"/>
        <vers num="2.6.23.15"/>
        <vers num="2.6.23.16"/>
        <vers num="2.6.23.17"/>
        <vers num="2.6.23.8"/>
        <vers num="2.6.23.9"/>
        <vers num="2.6.23_rc1"/>
        <vers num="2.6.24"/>
        <vers num="2.6.24.1"/>
        <vers num="2.6.24.2"/>
        <vers num="2.6.24.3"/>
        <vers num="2.6.24.4"/>
        <vers num="2.6.24.5"/>
        <vers num="2.6.24.6"/>
        <vers num="2.6.24.7"/>
        <vers num="2.6.24_rc1"/>
        <vers num="2.6.24_rc4"/>
        <vers num="2.6.24_rc5"/>
        <vers num="2.6.25" edition=""/>
        <vers num="2.6.25" edition=":x86_64"/>
        <vers num="2.6.25.1" edition=""/>
        <vers num="2.6.25.1" edition=":x86_64"/>
        <vers num="2.6.25.10" edition=""/>
        <vers num="2.6.25.10" edition=":x86_64"/>
        <vers num="2.6.25.11" edition=""/>
        <vers num="2.6.25.11" edition=":x86_64"/>
        <vers num="2.6.25.12" edition=""/>
        <vers num="2.6.25.12" edition=":x86_64"/>
        <vers num="2.6.25.13"/>
        <vers num="2.6.25.14"/>
        <vers num="2.6.25.15"/>
        <vers num="2.6.25.16"/>
        <vers num="2.6.25.17"/>
        <vers num="2.6.25.2" edition=""/>
        <vers num="2.6.25.2" edition=":x86_64"/>
        <vers num="2.6.25.3" edition=""/>
        <vers num="2.6.25.3" edition=":x86_64"/>
        <vers num="2.6.25.4" edition=""/>
        <vers num="2.6.25.4" edition=":x86_64"/>
        <vers num="2.6.25.5" edition=""/>
        <vers num="2.6.25.5" edition=":x86_64"/>
        <vers num="2.6.25.6" edition=""/>
        <vers num="2.6.25.6" edition=":x86_64"/>
        <vers num="2.6.25.7" edition=""/>
        <vers num="2.6.25.7" edition=":x86_64"/>
        <vers num="2.6.25.8" edition=""/>
        <vers num="2.6.25.8" edition=":x86_64"/>
        <vers num="2.6.25.9" edition=""/>
        <vers num="2.6.25.9" edition=":x86_64"/>
        <vers num="2.6.26"/>
        <vers num="2.6.26.1"/>
        <vers num="2.6.26.2"/>
        <vers num="2.6.26.3"/>
        <vers num="2.6.26.4"/>
        <vers num="2.6.26.5"/>
        <vers num="2.6.27"/>
        <vers prev="1" num="2.6.28"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0270" published="2009-01-26" name="CVE-2009-0270" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in PXEService.exe in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier allows remote attackers to execute arbitrary code via a large PXE protocol request in a UDP packet.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.fujitsu.com/global/services/computing/server/primequest/products/os/windows-server-2008-2.html" source="CONFIRM" patch="1" adv="1">http://www.fujitsu.com/global/services/computing/server/primequest/products/os/windows-server-2008-2.html</ref>
      <ref url="http://www.wintercore.com/advisories/advisory_W010109.html" source="MISC">http://www.wintercore.com/advisories/advisory_W010109.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0176" source="VUPEN">ADV-2009-0176</ref>
      <ref url="http://www.securityfocus.com/bid/33342" source="BID">33342</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500172/100/0/threaded" source="BUGTRAQ">20090119 [Wintercore Research ] Fujitsu SystemcastWizard Lite PXEService Remote Buffer Overflow.</ref>
      <ref url="http://secunia.com/advisories/33594" source="SECUNIA" adv="1">33594</ref>
      <ref url="http://osvdb.org/51486" source="OSVDB">51486</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fujitsu" name="systemcastwizard_lite">
        <vers num="1.7"/>
        <vers num="1.8"/>
        <vers num="1.8a"/>
        <vers num="1.9"/>
        <vers num="2.0"/>
        <vers prev="1" num="2.0a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0271" published="2009-01-26" name="CVE-2009-0271" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the TFTP service in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier allows remote attackers to read arbitrary files via directory traversal sequences in unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33344" source="BID" patch="1">33344</ref>
      <ref url="http://www.fujitsu.com/global/services/computing/server/primequest/products/os/windows-server-2008-2.html" source="CONFIRM" patch="1" adv="1">http://www.fujitsu.com/global/services/computing/server/primequest/products/os/windows-server-2008-2.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0176" source="VUPEN">ADV-2009-0176</ref>
      <ref url="http://secunia.com/advisories/33594" source="SECUNIA" adv="1">33594</ref>
      <ref url="http://osvdb.org/51487" source="OSVDB">51487</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fujitsu" name="systemcastwizard_lite">
        <vers num="1.7"/>
        <vers num="1.8"/>
        <vers num="1.8a"/>
        <vers num="1.9"/>
        <vers num="2.0"/>
        <vers num="2.0a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0272" published="2009-02-02" name="CVE-2009-0272" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in Novell GroupWise WebAccess 6.5x, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 allows remote attackers to insert e-mail forwarding rules, and modify unspecified other configuration settings, as arbitrary users via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500569/100/0/threaded" source="BUGTRAQ">20090130 PR08-21: Cross-site Request Forgery (CSRF) on Novell GroupWise WebAccess allows email theft and other attacks</ref>
      <ref url="http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr08-21" source="MISC">http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr08-21</ref>
      <ref url="http://www.novell.com/support/search.do?usemicrosite=true&amp;searchString=7002319" source="CONFIRM" adv="1">http://www.novell.com/support/search.do?usemicrosite=true&amp;searchString=7002319</ref>
      <ref url="http://secunia.com/advisories/33744" source="SECUNIA">33744</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise">
        <vers num="6.5"/>
        <vers num="7.0"/>
        <vers num="7.01"/>
        <vers num="7.02x"/>
        <vers num="7.03" edition="hp1a"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0273" published="2009-02-02" name="CVE-2009-0273" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Novell GroupWise WebAccess 6.5x, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 allow remote attackers to inject arbitrary web script or HTML via the (1) User.id and (2) Library.queryText parameters to gw/webacc, and other vectors involving (3) HTML e-mail and (4) HTML attachments.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33541" source="BID">33541</ref>
      <ref url="http://www.securityfocus.com/bid/33537" source="BID">33537</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500575/100/0/threaded" source="BUGTRAQ">20090130 PR08-23: XSS on Novell GroupWise WebAccess</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500572/100/0/threaded" source="BUGTRAQ">20090130 PR08-22: Persistent XSS on Novell GroupWise WebAccess</ref>
      <ref url="http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr08-23" source="MISC">http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr08-23</ref>
      <ref url="http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr08-22" source="MISC">http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr08-22</ref>
      <ref url="http://www.novell.com/support/search.do?usemicrosite=true&amp;searchString=7002321" source="CONFIRM" adv="1">http://www.novell.com/support/search.do?usemicrosite=true&amp;searchString=7002321</ref>
      <ref url="http://www.novell.com/support/search.do?usemicrosite=true&amp;searchString=7002320" source="CONFIRM" adv="1">http://www.novell.com/support/search.do?usemicrosite=true&amp;searchString=7002320</ref>
      <ref url="http://secunia.com/advisories/33744" source="SECUNIA">33744</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise">
        <vers num="6.5"/>
        <vers num="7.0"/>
        <vers num="7.01"/>
        <vers num="7.02x"/>
        <vers num="7.03" edition="hp1a"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0274" published="2009-02-03" name="CVE-2009-0274" modified="2009-02-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in WebAccess in Novell GroupWise 6.5, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 might allow remote attackers to obtain sensitive information via a crafted URL, related to conversion of POST requests to GET requests.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33559" source="BID">33559</ref>
      <ref url="http://www.novell.com/support/viewContent.do?externalId=7002322" source="CONFIRM" adv="1">http://www.novell.com/support/viewContent.do?externalId=7002322</ref>
      <ref url="http://secunia.com/advisories/33744" source="SECUNIA" adv="1">33744</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise">
        <vers num="6.5"/>
        <vers num="7.0"/>
        <vers num="7.01"/>
        <vers num="7.02x"/>
        <vers num="7.03" edition="hp1a"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0275" published="2009-01-26" name="CVE-2009-0275" modified="2009-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into config/header via the header parameter.  NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2009-0250. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.osvdb.org/51412" source="OSVDB">51412</ref>
      <ref url="http://secunia.com/advisories/33531" source="SECUNIA">33531</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ryneezy" name="phosheezy">
        <vers num="0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0276" published="2009-02-03" name="CVE-2009-0276" modified="2009-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-domain vulnerability in the V8 JavaScript engine in Google Chrome before 1.0.154.46 allows remote attackers to bypass the Same Origin Policy via a crafted script that accesses another frame and reads its full URL and possibly other sensitive information, or modifies the URL of this frame.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://src.chromium.org/viewvc/chrome?view=rev&amp;revision=8524" source="CONFIRM">http://src.chromium.org/viewvc/chrome?view=rev&amp;revision=8524</ref>
      <ref url="http://sites.google.com/a/chromium.org/dev/getting-involved/dev-channel/release-notes" source="CONFIRM">http://sites.google.com/a/chromium.org/dev/getting-involved/dev-channel/release-notes</ref>
      <ref url="http://secunia.com/advisories/33754" source="SECUNIA" adv="1">33754</ref>
      <ref url="http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html" source="CONFIRM" adv="1">http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html</ref>
      <ref url="http://codereview.chromium.org/18531" source="CONFIRM">http://codereview.chromium.org/18531</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.152.1"/>
        <vers num="0.2.153.1"/>
        <vers num="0.3.154.0"/>
        <vers num="0.3.154.3"/>
        <vers num="0.4.154.18"/>
        <vers num="0.4.154.22"/>
        <vers num="0.4.154.31"/>
        <vers num="0.4.154.33"/>
        <vers num="1.0.154.36"/>
        <vers num="1.0.154.39"/>
        <vers num="1.0.154.42"/>
        <vers prev="1" num="1.0.154.43"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0277" published="2009-01-26" name="CVE-2009-0277" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the kernel in OpenSolaris snv_100 through snv_102 on the Sun UltraSPARC T2 and T2+ sun4v platforms allows local users to cause a denial of service (panic) via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-250066-1" source="SUNALERT" patch="1" adv="1">250066</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48164" source="XF">solaris-ultrasparct2-dos(48164)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0209" source="VUPEN">ADV-2009-0209</ref>
      <ref url="http://www.securityfocus.com/bid/33398" source="BID">33398</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_100" edition=""/>
        <vers num="snv_100" edition=":sparc"/>
        <vers num="snv_101" edition=""/>
        <vers num="snv_101" edition=":sparc"/>
        <vers num="snv_102" edition=""/>
        <vers num="snv_102" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0278" published="2009-01-26" name="CVE-2009-0278" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sun Java System Application Server (AS) 8.1 and 8.2 allows remote attackers to read the Web Application configuration files in the (1) WEB-INF or (2) META-INF directory via a malformed request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-245446-1" source="SUNALERT" patch="1" adv="1">245446</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-119166-35-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-119166-35-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48161" source="XF">javasystem-webinf-metainf-info-disclosure(48161)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0208" source="VUPEN">ADV-2009-0208</ref>
      <ref url="http://www.securityfocus.com/bid/33397" source="BID">33397</ref>
      <ref url="http://secunia.com/advisories/33725" source="SECUNIA">33725</ref>
      <ref url="http://osvdb.org/51604" source="OSVDB">51604</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_application_server">
        <vers num="8.1" edition=""/>
        <vers num="8.1" edition=":linux"/>
        <vers num="8.1" edition=":x86"/>
        <vers num="8.1" edition=":sparc"/>
        <vers num="8.1" edition=":windows"/>
        <vers num="8.2" edition=""/>
        <vers num="8.2" edition=":x86"/>
        <vers num="8.2" edition=":windows"/>
        <vers num="8.2" edition=":sparc"/>
        <vers num="8.2" edition=":linux"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0279" published="2009-01-27" name="CVE-2009-0279" modified="2009-01-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in comentar.php in Pardal CMS 0.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48175" source="XF">pardalcms-comentar-sql-injection(48175)</ref>
      <ref url="http://www.securityfocus.com/bid/33404" source="BID">33404</ref>
      <ref url="http://www.milw0rm.com/exploits/7851" source="MILW0RM">7851</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pardalcms" name="pardalcms">
        <vers num="0.01b"/>
        <vers num="0.01c"/>
        <vers num="0.1.1"/>
        <vers num="0.1.2"/>
        <vers num="0.1.3"/>
        <vers num="0.1a"/>
        <vers prev="1" num="0.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0280" published="2009-01-27" name="CVE-2009-0280" modified="2009-01-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the crypt cookie to 1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48172" source="XF">aspproject-cookie-security-bypass(48172)</ref>
      <ref url="http://www.securityfocus.com/bid/33401" source="BID">33401</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500292/100/0/threaded" source="BUGTRAQ">20090122 Asp-project Cookie Handling</ref>
      <ref url="http://www.milw0rm.com/exploits/7850" source="MILW0RM">7850</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asp-project" name="asp-project">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0281" published="2009-01-27" name="CVE-2009-0281" modified="2009-01-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.aspx in WarHound Walking Club allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48061" source="XF">walkingclub-login-sql-injection(48061)</ref>
      <ref url="http://www.securityfocus.com/bid/33317" source="BID">33317</ref>
      <ref url="http://www.milw0rm.com/exploits/7802" source="MILW0RM">7802</ref>
    </refs>
    <vuln_soft>
      <prod vendor="warhound" name="walking_club">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0282" published="2009-01-27" name="CVE-2009-0282" modified="2010-12-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in Ralink Technology USB wireless adapter (RT73) 3.08 for Windows, and other wireless card drivers including rt2400, rt2500, rt2570, and rt61, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Probe Request packet with a long SSID, possibly related to an integer signedness error.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33340" source="BID">33340</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500168/100/0/threaded" source="BUGTRAQ">20090118 Ralinktech wireless cards drivers vulnerability</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1714" source="DEBIAN">DSA-1714</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1713" source="DEBIAN">DSA-1713</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1712" source="DEBIAN">DSA-1712</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-08.xml" source="GENTOO">GLSA-200907-08</ref>
      <ref url="http://secunia.com/advisories/35743" source="SECUNIA" adv="1">35743</ref>
      <ref url="http://secunia.com/advisories/33699" source="SECUNIA" adv="1">33699</ref>
      <ref url="http://secunia.com/advisories/33592" source="SECUNIA" adv="1">33592</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=512995" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=512995</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ralinktech" name="rt73">
        <vers num="3.08"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0283" published="2009-01-27" name="CVE-2009-0283" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in err.asp in Oblog allows remote attackers to inject arbitrary web script or HTML via the message parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33416" source="BID">33416</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500397/100/0/threaded" source="BUGTRAQ">20090124 Re: Oblog XSS valnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500349/100/0/threaded" source="BUGTRAQ">20090123 Oblog XSS valnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aobosoft" name="oblog">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0284" published="2009-01-27" name="CVE-2009-0284" modified="2009-06-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in category.php in Flax Article Manager 1.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33422" source="BID">33422</ref>
      <ref url="http://www.milw0rm.com/exploits/7862" source="MILW0RM">7862</ref>
      <ref url="http://www.flaxweb.com/products/articles" source="CONFIRM">http://www.flaxweb.com/products/articles</ref>
      <ref url="http://secunia.com/advisories/33625" source="SECUNIA" adv="1">33625</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flaxweb" name="flax_article_manager">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0285" published="2009-01-27" name="CVE-2009-0285" modified="2009-01-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in error.asp in BBSXP 5.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48187" source="XF">bbsxp-error-xss(48187)</ref>
      <ref url="http://www.securityfocus.com/bid/33411" source="BID">33411</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500336/100/0/threaded" source="BUGTRAQ">20090123 BBSxp Xss vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bbsxp" name="bbsxp">
        <vers prev="1" num="5.13"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0286" published="2009-01-27" name="CVE-2009-0286" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Directory traversal vulnerability in upgrade/index.php in OpenGoo 1.1, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the form_data[script_class] parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33421" source="BID">33421</ref>
      <ref url="http://www.milw0rm.com/exploits/7863" source="MILW0RM">7863</ref>
      <ref url="http://osvdb.org/51635" source="OSVDB">51635</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opengoo" name="opengoo">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0287" published="2009-01-27" name="CVE-2009-0287" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in lib/patUser.php in KEEP Toolkit before 2.5.1 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33425" source="BID" patch="1">33425</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=655845&amp;group_id=227492" source="CONFIRM" patch="1" adv="1">http://sourceforge.net/project/shownotes.php?release_id=655845&amp;group_id=227492</ref>
      <ref url="http://secunia.com/advisories/33652" source="SECUNIA" adv="1">33652</ref>
      <ref url="http://osvdb.org/51623" source="OSVDB">51623</ref>
      <ref url="http://keeptoolkit.svn.sourceforge.net/viewvc/keeptoolkit?view=rev&amp;revision=56" source="CONFIRM">http://keeptoolkit.svn.sourceforge.net/viewvc/keeptoolkit?view=rev&amp;revision=56</ref>
    </refs>
    <vuln_soft>
      <prod vendor="keep_toolkit" name="keep_toolkit">
        <vers num="2.1"/>
        <vers prev="1" num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0288" published="2009-01-27" name="CVE-2009-0288" modified="2009-01-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in k23productions TFTPUtil GUI 1.2.0 and 1.3.0 allows remote attackers to read arbitrary files outside the TFTP root directory via directory traversal sequences in a GET request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33287" source="BID" patch="1">33287</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=894598" source="CONFIRM" patch="1">http://sourceforge.net/forum/forum.php?forum_id=894598</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48019" source="XF">tftputil-tftpget-directory-traversal(48019)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500106/100/0/threaded" source="BUGTRAQ">20090115 TFTPUtil GUI TFTP Directory Traversal</ref>
      <ref url="http://www.princeofnigeria.org/blogs/index.php/2009/01/14/tftputil-gui-tftp-directory-traversal" source="MISC">http://www.princeofnigeria.org/blogs/index.php/2009/01/14/tftputil-gui-tftp-directory-traversal</ref>
      <ref url="http://secunia.com/advisories/33561" source="SECUNIA" adv="1">33561</ref>
    </refs>
    <vuln_soft>
      <prod vendor="windows_tftp_utility" name="tftputil">
        <vers num="1.2.0"/>
        <vers num="1.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0289" published="2009-01-27" name="CVE-2009-0289" modified="2009-01-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">k23productions TFTPUtil GUI 1.2.0 and 1.3.0 allows remote attackers to cause a denial of service (service crash) via a long filename in a crafted request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33289" source="BID" patch="1">33289</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=894598" source="MISC" patch="1">http://sourceforge.net/forum/forum.php?forum_id=894598</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500107/100/0/threaded" source="BUGTRAQ">20090115 TFTPUtil GUI TFTP Server Denial of Service Vulnerability</ref>
      <ref url="http://www.princeofnigeria.org/blogs/index.php/2009/01/14/tftputil-gui-tftp-server-denial-of-servi?blog=1" source="MISC">http://www.princeofnigeria.org/blogs/index.php/2009/01/14/tftputil-gui-tftp-server-denial-of-servi?blog=1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="windows_tftp_utility" name="tftputil">
        <vers num="1.2.0"/>
        <vers num="1.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0290" published="2009-01-27" name="CVE-2009-0290" modified="2009-01-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the g4_path parameter.  NOTE: in some environments, this can be leveraged for remote code execution via a data: URI or a UNC share pathname.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48015" source="XF">gnuboard-common-file-include(48015)</ref>
      <ref url="http://www.securityfocus.com/bid/33304" source="BID">33304</ref>
      <ref url="http://www.milw0rm.com/exploits/7792" source="MILW0RM">7792</ref>
      <ref url="http://secunia.com/advisories/33564" source="SECUNIA" adv="1">33564</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sir" name="gnuboard">
        <vers num="4.31.03"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0291" published="2009-01-27" name="CVE-2009-0291" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in fc.php in OpenX 2.6.3 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the MAX_type parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33458" source="BID">33458</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500411/100/0/threaded" source="BUGTRAQ">20090127 OpenX 2.6.3 - Local File Inclusion</ref>
      <ref url="http://www.milw0rm.com/exploits/7883" source="MILW0RM">7883</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openx" name="openx">
        <vers num="2.6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0292" published="2009-01-27" name="CVE-2009-0292" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in show_cat2.php in SHOP-INET 4 allows remote attackers to execute arbitrary SQL commands via the grid parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/7874" source="MILW0RM">7874</ref>
      <ref url="http://secunia.com/advisories/33660" source="SECUNIA" adv="1">33660</ref>
      <ref url="http://osvdb.org/51615" source="OSVDB">51615</ref>
    </refs>
    <vuln_soft>
      <prod vendor="shop-inet" name="shop-inet">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0293" published="2009-01-27" name="CVE-2009-0293" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in profile_view.php in Wazzum Dating Software, possibly 2.0, allows remote attackers to execute arbitrary SQL commands via the userid parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33461" source="BID">33461</ref>
      <ref url="http://www.milw0rm.com/exploits/7877" source="MILW0RM">7877</ref>
      <ref url="http://secunia.com/advisories/33654" source="SECUNIA" adv="1">33654</ref>
      <ref url="http://osvdb.org/51625" source="OSVDB">51625</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wazzum" name="wazzum_dating_software">
        <vers num="_nil_"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0294" published="2009-01-27" name="CVE-2009-0294" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in WB News 2.0.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the config[installdir] parameter to (1) search.php, (2) archive.php, (3) comments.php, and (4) news.php; (5) News.php, (6) SendFriend.php, (7) Archive.php, and (8) Comments.php in base/; and possibly other components, different vectors than CVE-2007-1288.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33434" source="BID">33434</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500398/100/0/threaded" source="BUGTRAQ">20090125 WB News v2.0.X Remote File include ..</ref>
      <ref url="http://secunia.com/advisories/33691" source="SECUNIA" adv="1">33691</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webmobo" name="wbnews">
        <vers num="2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0295" published="2009-01-27" name="CVE-2009-0295" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Information Technology Light Poll Information (ITLPoll) 2.7 Stable 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33452" source="BID">33452</ref>
      <ref url="http://www.milw0rm.com/exploits/7867" source="MILW0RM">7867</ref>
      <ref url="http://secunia.com/advisories/33666" source="SECUNIA" adv="1">33666</ref>
      <ref url="http://osvdb.org/51616" source="OSVDB">51616</ref>
    </refs>
    <vuln_soft>
      <prod vendor="itlpoll" name="itpoll">
        <vers num="2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0296" published="2009-01-27" name="CVE-2009-0296" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in shop_display_products.php in Script Toko Online 5.01 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/7873" source="MILW0RM">7873</ref>
      <ref url="http://secunia.com/advisories/33661" source="SECUNIA" adv="1">33661</ref>
      <ref url="http://osvdb.org/51630" source="OSVDB">51630</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gempar" name="script_toko_online">
        <vers num="5.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0297" published="2009-01-27" name="CVE-2009-0297" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login_check.asp in ClickAuction allows remote attackers to execute arbitrary SQL commands via the (1) txtEmail and (2) txtPassword parameters.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/7880" source="MILW0RM">7880</ref>
      <ref url="http://secunia.com/advisories/33647" source="SECUNIA" adv="1">33647</ref>
      <ref url="http://osvdb.org/51626" source="OSVDB">51626</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clicktech" name="clickauction">
        <vers num="_nil_"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0298" published="2009-01-27" name="CVE-2009-0298" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in MW6 Technologies Barcode ActiveX control (Barcode.MW6Barcode.1, Barcode.dll) 3.0.0.1 allows remote attackers to execute arbitrary code via a long Supplement property.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33451" source="BID">33451</ref>
      <ref url="http://www.milw0rm.com/exploits/7869" source="MILW0RM">7869</ref>
      <ref url="http://secunia.com/advisories/33663" source="SECUNIA" adv="1">33663</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mw6_technologies" name="barcode_activex">
        <vers num="3.0.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0299" published="2009-01-27" name="CVE-2009-0299" modified="2009-10-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33460" source="BID">33460</ref>
      <ref url="http://www.milw0rm.com/exploits/9236" source="MILW0RM">9236</ref>
      <ref url="http://www.milw0rm.com/exploits/7878" source="MILW0RM">7878</ref>
      <ref url="http://secunia.com/advisories/33649" source="SECUNIA" adv="1">33649</ref>
      <ref url="http://osvdb.org/51628" source="OSVDB">51628</ref>
    </refs>
    <vuln_soft>
      <prod vendor="groonesworld" name="glinks">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2009-0300" reject="1" published="2009-01-27" name="CVE-2009-0300" modified="2009-01-29">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-2636.  Reason: This candidate is a duplicate of CVE-2006-2636.  Notes: All CVE users should reference CVE-2006-2636 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0301" published="2009-01-27" name="CVE-2009-0301" modified="2009-01-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple insecure method vulnerabilities in the FlexCell.Grid ActiveX control (FlexCell.ocx) in FlexCell Grid Control 5.6.9 allow remote attackers to create and overwrite arbitrary files via the (1) SaveFile and (2) ExportToXML methods.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33453" source="BID">33453</ref>
      <ref url="http://www.milw0rm.com/exploits/7868" source="MILW0RM">7868</ref>
      <ref url="http://secunia.com/advisories/33664" source="SECUNIA" adv="1">33664</ref>
    </refs>
    <vuln_soft>
      <prod vendor="grid2000" name="flexcell_grid_control">
        <vers num="5.6.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0302" published="2009-01-27" name="CVE-2009-0302" modified="2012-08-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Downloads module for PHP-Nuke 8.0 8.1.0.3.5b and earlier allows remote authenticated users to execute arbitrary SQL commands via the url parameter in the Add operation to modules.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/71475" source="XF">phpnuke-uri-sql-injection(71475)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48186" source="XF">downloads-module-sql-injection(48186)</ref>
      <ref url="http://www.securityfocus.com/bid/50770" source="BID">50770</ref>
      <ref url="http://www.securityfocus.com/bid/33410" source="BID">33410</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500335/100/0/threaded" source="BUGTRAQ">20090123 PHP-Nuke 8.0 Downloads Blind Sql Injection</ref>
      <ref url="http://www.exploit-db.com/exploits/18148" source="EXPLOIT-DB">18148</ref>
      <ref url="http://osvdb.org/77349" source="OSVDB">77349</ref>
      <ref url="http://osvdb.org/51633" source="OSVDB">51633</ref>
      <ref url="http://1337day.com/exploits/15481" source="MISC">http://1337day.com/exploits/15481</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php-nuke" name="downloads_module">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0303" published="2009-01-27" name="CVE-2009-0303" modified="2009-01-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Web Help Desk before 9.1.18 allows remote attackers to inject arbitrary web script or HTML via vectors related to "encoded JavaScript" and Helpdesk.woa.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33429" source="BID">33429</ref>
      <ref url="http://updates.webhelpdesk.com/weblog/updates/StableReleases/2009/01/23/911812309.html" source="CONFIRM" adv="1">http://updates.webhelpdesk.com/weblog/updates/StableReleases/2009/01/23/911812309.html</ref>
      <ref url="http://secunia.com/advisories/33651" source="SECUNIA" adv="1">33651</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webhelpdesk" name="web_help_desk">
        <vers num="8.0.20"/>
        <vers num="8.0.21"/>
        <vers num="8.0.22"/>
        <vers num="8.2.0"/>
        <vers num="8.2.0.1"/>
        <vers num="8.2.0.10"/>
        <vers num="8.2.0.2"/>
        <vers num="8.2.0.3"/>
        <vers num="8.2.0.4"/>
        <vers num="8.2.0.5"/>
        <vers num="8.2.0.6"/>
        <vers num="8.2.0.7"/>
        <vers num="8.2.0.8"/>
        <vers num="8.2.0.9"/>
        <vers num="8.2.1.1"/>
        <vers num="8.2.1.2"/>
        <vers num="8.2.1.3"/>
        <vers num="8.2.1.4"/>
        <vers num="8.2.1.5"/>
        <vers num="8.2.2"/>
        <vers num="8.2.3"/>
        <vers num="8.2.3.1"/>
        <vers num="8.2.3.2"/>
        <vers num="8.2.3.3"/>
        <vers num="8.2.3.4"/>
        <vers num="8.2.4"/>
        <vers num="8.2.4.1"/>
        <vers num="8.2.4.2"/>
        <vers num="8.2.4.3"/>
        <vers num="8.3.0.1"/>
        <vers num="8.3.0.2"/>
        <vers num="8.3.0.3"/>
        <vers num="8.3.0.4"/>
        <vers num="8.3.0.5"/>
        <vers num="8.3.1"/>
        <vers num="8.3.1.1"/>
        <vers num="8.3.1.2"/>
        <vers num="8.3.1.3"/>
        <vers num="8.3.2"/>
        <vers num="8.3.3"/>
        <vers num="8.3.3.1"/>
        <vers num="8.3.3.2"/>
        <vers num="8.3.3.3"/>
        <vers num="8.3.3.4"/>
        <vers num="8.3.4.0"/>
        <vers num="8.3.4.1"/>
        <vers num="8.3.4.2"/>
        <vers num="8.3.5.1"/>
        <vers num="8.3.5.2"/>
        <vers num="8.3.5.3"/>
        <vers num="8.3.5.4"/>
        <vers num="8.3.5.5"/>
        <vers num="8.3.5.6"/>
        <vers num="8.3.6"/>
        <vers num="8.3.6.1"/>
        <vers num="8.4.1.0"/>
        <vers num="8.4.1.1"/>
        <vers num="8.4.1.2"/>
        <vers num="8.4.1.3"/>
        <vers num="8.4.1.4"/>
        <vers num="8.4.1.5"/>
        <vers num="8.4.1.6"/>
        <vers num="8.4.1.7"/>
        <vers num="8.4.1.8"/>
        <vers num="8.4.1.9"/>
        <vers num="8.4.2.0"/>
        <vers num="8.4.2.1"/>
        <vers num="8.4.2.2"/>
        <vers num="8.4.2.3"/>
        <vers num="8.4.3.0"/>
        <vers num="8.4.3.1"/>
        <vers num="8.4.3.2"/>
        <vers num="8.4.3.3"/>
        <vers num="8.4.3.4"/>
        <vers num="8.4.3.5"/>
        <vers num="8.4.3.6"/>
        <vers num="8.4.3.7"/>
        <vers num="8.4.4"/>
        <vers num="8.4.5"/>
        <vers num="8.4.5.1"/>
        <vers num="8.4.5.2"/>
        <vers num="8.4.6.0"/>
        <vers num="8.4.6.1"/>
        <vers num="8.4.6.10"/>
        <vers num="8.4.6.2"/>
        <vers num="8.4.6.3"/>
        <vers num="8.4.6.4"/>
        <vers num="8.4.6.5"/>
        <vers num="8.4.6.6"/>
        <vers num="8.4.6.7"/>
        <vers num="8.4.6.8"/>
        <vers num="9.1.0"/>
        <vers num="9.1.1"/>
        <vers num="9.1.10"/>
        <vers num="9.1.11"/>
        <vers num="9.1.12"/>
        <vers num="9.1.13"/>
        <vers num="9.1.14"/>
        <vers num="9.1.15"/>
        <vers num="9.1.16"/>
        <vers prev="1" num="9.1.17"/>
        <vers num="9.1.2"/>
        <vers num="9.1.4"/>
        <vers num="9.1.5"/>
        <vers num="9.1.6"/>
        <vers num="9.1.7"/>
        <vers num="9.1.8"/>
        <vers num="9.1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0304" published="2009-01-27" name="CVE-2009-0304" modified="2012-02-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The kernel in Sun Solaris 10 and 11 snv_101b, and OpenSolaris before snv_108, allows remote attackers to cause a denial of service (system crash) via a crafted IPv6 packet, related to an "insufficient validation security vulnerability," as demonstrated by SunOSipv6.c.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48208" source="XF">sun-solaris-ipv6packets-dos(48208)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0232" source="VUPEN" adv="1">ADV-2009-0232</ref>
      <ref url="http://www.securityfocus.com/bid/33435" source="BID">33435</ref>
      <ref url="http://www.milw0rm.com/exploits/7865" source="MILW0RM">7865</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-251006-1" source="SUNALERT" adv="1">251006</ref>
      <ref url="http://securitytracker.com/id?1021635" source="SECTRACK">1021635</ref>
      <ref url="http://secunia.com/advisories/33605" source="SECUNIA" adv="1">33605</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2009-January/067709.html" source="FULLDISC">20090126 Solaris Devs Are Smoking Pot</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_01" edition=""/>
        <vers num="snv_01" edition=":sparc"/>
        <vers num="snv_01" edition=":x86"/>
        <vers num="snv_02" edition=""/>
        <vers num="snv_02" edition=":sparc"/>
        <vers num="snv_02" edition=":x86"/>
        <vers num="snv_03" edition=""/>
        <vers num="snv_03" edition=":x86"/>
        <vers num="snv_03" edition=":sparc"/>
        <vers num="snv_04" edition=""/>
        <vers num="snv_04" edition=":x86"/>
        <vers num="snv_04" edition=":sparc"/>
        <vers num="snv_05" edition=""/>
        <vers num="snv_05" edition=":sparc"/>
        <vers num="snv_05" edition=":x86"/>
        <vers num="snv_06" edition=""/>
        <vers num="snv_06" edition=":sparc"/>
        <vers num="snv_06" edition=":x86"/>
        <vers num="snv_07" edition=""/>
        <vers num="snv_07" edition=":sparc"/>
        <vers num="snv_07" edition=":x86"/>
        <vers num="snv_08" edition=""/>
        <vers num="snv_08" edition=":x86"/>
        <vers num="snv_08" edition=":sparc"/>
        <vers num="snv_09" edition=""/>
        <vers num="snv_09" edition=":x86"/>
        <vers num="snv_09" edition=":sparc"/>
        <vers num="snv_10" edition=""/>
        <vers num="snv_10" edition=":x86"/>
        <vers num="snv_10" edition=":sparc"/>
        <vers num="snv_100" edition=""/>
        <vers num="snv_100" edition=":sparc"/>
        <vers num="snv_100" edition=":x86"/>
        <vers num="snv_101" edition=""/>
        <vers num="snv_101" edition=":x86"/>
        <vers num="snv_101" edition=":sparc"/>
        <vers num="snv_101b"/>
        <vers num="snv_102" edition=""/>
        <vers num="snv_102" edition=":sparc"/>
        <vers num="snv_102" edition=":x86"/>
        <vers num="snv_103" edition=""/>
        <vers num="snv_103" edition=":x86"/>
        <vers num="snv_103" edition=":sparc"/>
        <vers num="snv_104" edition=""/>
        <vers num="snv_104" edition=":x86"/>
        <vers num="snv_104" edition=":sparc"/>
        <vers num="snv_105" edition=""/>
        <vers num="snv_105" edition=":x86"/>
        <vers num="snv_105" edition=":sparc"/>
        <vers num="snv_106" edition=""/>
        <vers num="snv_106" edition=":sparc"/>
        <vers num="snv_106" edition=":x86"/>
        <vers prev="1" num="snv_107" edition=""/>
        <vers prev="1" num="snv_107" edition=":x86"/>
        <vers prev="1" num="snv_107" edition=":sparc"/>
        <vers num="snv_11" edition=""/>
        <vers num="snv_11" edition=":x86"/>
        <vers num="snv_11" edition=":sparc"/>
        <vers num="snv_12" edition=""/>
        <vers num="snv_12" edition=":x86"/>
        <vers num="snv_12" edition=":sparc"/>
        <vers num="snv_13" edition=""/>
        <vers num="snv_13" edition=":x86"/>
        <vers num="snv_13" edition=":sparc"/>
        <vers num="snv_14" edition=""/>
        <vers num="snv_14" edition=":sparc"/>
        <vers num="snv_14" edition=":x86"/>
        <vers num="snv_15" edition=""/>
        <vers num="snv_15" edition=":x86"/>
        <vers num="snv_15" edition=":sparc"/>
        <vers num="snv_16" edition=""/>
        <vers num="snv_16" edition=":sparc"/>
        <vers num="snv_16" edition=":x86"/>
        <vers num="snv_17" edition=""/>
        <vers num="snv_17" edition=":x86"/>
        <vers num="snv_17" edition=":sparc"/>
        <vers num="snv_18" edition=""/>
        <vers num="snv_18" edition=":x86"/>
        <vers num="snv_18" edition=":sparc"/>
        <vers num="snv_19" edition=""/>
        <vers num="snv_19" edition=":sparc"/>
        <vers num="snv_19" edition=":x86"/>
        <vers num="snv_20" edition=""/>
        <vers num="snv_20" edition=":x86"/>
        <vers num="snv_20" edition=":sparc"/>
        <vers num="snv_21" edition=""/>
        <vers num="snv_21" edition=":sparc"/>
        <vers num="snv_21" edition=":x86"/>
        <vers num="snv_22" edition=""/>
        <vers num="snv_22" edition=":sparc"/>
        <vers num="snv_22" edition=":x86"/>
        <vers num="snv_23" edition=""/>
        <vers num="snv_23" edition=":sparc"/>
        <vers num="snv_23" edition=":x86"/>
        <vers num="snv_24" edition=""/>
        <vers num="snv_24" edition=":sparc"/>
        <vers num="snv_24" edition=":x86"/>
        <vers num="snv_25" edition=""/>
        <vers num="snv_25" edition=":x86"/>
        <vers num="snv_25" edition=":sparc"/>
        <vers num="snv_26" edition=""/>
        <vers num="snv_26" edition=":x86"/>
        <vers num="snv_26" edition=":sparc"/>
        <vers num="snv_27" edition=""/>
        <vers num="snv_27" edition=":sparc"/>
        <vers num="snv_27" edition=":x86"/>
        <vers num="snv_28" edition=""/>
        <vers num="snv_28" edition=":x86"/>
        <vers num="snv_28" edition=":sparc"/>
        <vers num="snv_29" edition=""/>
        <vers num="snv_29" edition=":x86"/>
        <vers num="snv_29" edition=":sparc"/>
        <vers num="snv_30" edition=""/>
        <vers num="snv_30" edition=":sparc"/>
        <vers num="snv_30" edition=":x86"/>
        <vers num="snv_31" edition=""/>
        <vers num="snv_31" edition=":sparc"/>
        <vers num="snv_31" edition=":x86"/>
        <vers num="snv_32" edition=""/>
        <vers num="snv_32" edition=":x86"/>
        <vers num="snv_32" edition=":sparc"/>
        <vers num="snv_33" edition=""/>
        <vers num="snv_33" edition=":x86"/>
        <vers num="snv_33" edition=":sparc"/>
        <vers num="snv_34" edition=""/>
        <vers num="snv_34" edition=":sparc"/>
        <vers num="snv_34" edition=":x86"/>
        <vers num="snv_35" edition=""/>
        <vers num="snv_35" edition=":sparc"/>
        <vers num="snv_35" edition=":x86"/>
        <vers num="snv_36" edition=""/>
        <vers num="snv_36" edition=":x86"/>
        <vers num="snv_36" edition=":sparc"/>
        <vers num="snv_37" edition=""/>
        <vers num="snv_37" edition=":sparc"/>
        <vers num="snv_37" edition=":x86"/>
        <vers num="snv_38" edition=""/>
        <vers num="snv_38" edition=":sparc"/>
        <vers num="snv_38" edition=":x86"/>
        <vers num="snv_39" edition=""/>
        <vers num="snv_39" edition=":sparc"/>
        <vers num="snv_39" edition=":x86"/>
        <vers num="snv_40" edition=""/>
        <vers num="snv_40" edition=":sparc"/>
        <vers num="snv_40" edition=":x86"/>
        <vers num="snv_41" edition=""/>
        <vers num="snv_41" edition=":sparc"/>
        <vers num="snv_41" edition=":x86"/>
        <vers num="snv_42" edition=""/>
        <vers num="snv_42" edition=":x86"/>
        <vers num="snv_42" edition=":sparc"/>
        <vers num="snv_43" edition=""/>
        <vers num="snv_43" edition=":sparc"/>
        <vers num="snv_43" edition=":x86"/>
        <vers num="snv_44" edition=""/>
        <vers num="snv_44" edition=":x86"/>
        <vers num="snv_44" edition=":sparc"/>
        <vers num="snv_45" edition=""/>
        <vers num="snv_45" edition=":x86"/>
        <vers num="snv_45" edition=":sparc"/>
        <vers num="snv_46" edition=""/>
        <vers num="snv_46" edition=":x86"/>
        <vers num="snv_46" edition=":sparc"/>
        <vers num="snv_47" edition=""/>
        <vers num="snv_47" edition=":x86"/>
        <vers num="snv_47" edition=":sparc"/>
        <vers num="snv_48" edition=""/>
        <vers num="snv_48" edition=":sparc"/>
        <vers num="snv_48" edition=":x86"/>
        <vers num="snv_49" edition=""/>
        <vers num="snv_49" edition=":sparc"/>
        <vers num="snv_49" edition=":x86"/>
        <vers num="snv_50" edition=""/>
        <vers num="snv_50" edition=":sparc"/>
        <vers num="snv_50" edition=":x86"/>
        <vers num="snv_51" edition=""/>
        <vers num="snv_51" edition=":sparc"/>
        <vers num="snv_51" edition=":x86"/>
        <vers num="snv_52" edition=""/>
        <vers num="snv_52" edition=":sparc"/>
        <vers num="snv_52" edition=":x86"/>
        <vers num="snv_53" edition=""/>
        <vers num="snv_53" edition=":sparc"/>
        <vers num="snv_53" edition=":x86"/>
        <vers num="snv_54" edition=""/>
        <vers num="snv_54" edition=":x86"/>
        <vers num="snv_54" edition=":sparc"/>
        <vers num="snv_55" edition=""/>
        <vers num="snv_55" edition=":sparc"/>
        <vers num="snv_55" edition=":x86"/>
        <vers num="snv_56" edition=""/>
        <vers num="snv_56" edition=":x86"/>
        <vers num="snv_56" edition=":sparc"/>
        <vers num="snv_57" edition=""/>
        <vers num="snv_57" edition=":x86"/>
        <vers num="snv_57" edition=":sparc"/>
        <vers num="snv_58" edition=""/>
        <vers num="snv_58" edition=":sparc"/>
        <vers num="snv_58" edition=":x86"/>
        <vers num="snv_59" edition=""/>
        <vers num="snv_59" edition=":sparc"/>
        <vers num="snv_59" edition=":x86"/>
        <vers num="snv_60" edition=""/>
        <vers num="snv_60" edition=":x86"/>
        <vers num="snv_60" edition=":sparc"/>
        <vers num="snv_61" edition=""/>
        <vers num="snv_61" edition=":sparc"/>
        <vers num="snv_61" edition=":x86"/>
        <vers num="snv_62" edition=""/>
        <vers num="snv_62" edition=":x86"/>
        <vers num="snv_62" edition=":sparc"/>
        <vers num="snv_63" edition=""/>
        <vers num="snv_63" edition=":sparc"/>
        <vers num="snv_63" edition=":x86"/>
        <vers num="snv_64" edition=""/>
        <vers num="snv_64" edition=":x86"/>
        <vers num="snv_64" edition=":sparc"/>
        <vers num="snv_65" edition=""/>
        <vers num="snv_65" edition=":x86"/>
        <vers num="snv_65" edition=":sparc"/>
        <vers num="snv_66" edition=""/>
        <vers num="snv_66" edition=":x86"/>
        <vers num="snv_66" edition=":sparc"/>
        <vers num="snv_67" edition=""/>
        <vers num="snv_67" edition=":sparc"/>
        <vers num="snv_67" edition=":x86"/>
        <vers num="snv_68" edition=""/>
        <vers num="snv_68" edition=":x86"/>
        <vers num="snv_68" edition=":sparc"/>
        <vers num="snv_69" edition=""/>
        <vers num="snv_69" edition=":sparc"/>
        <vers num="snv_69" edition=":x86"/>
        <vers num="snv_70" edition=""/>
        <vers num="snv_70" edition=":sparc"/>
        <vers num="snv_70" edition=":x86"/>
        <vers num="snv_71" edition=""/>
        <vers num="snv_71" edition=":x86"/>
        <vers num="snv_71" edition=":sparc"/>
        <vers num="snv_72" edition=""/>
        <vers num="snv_72" edition=":x86"/>
        <vers num="snv_72" edition=":sparc"/>
        <vers num="snv_73" edition=""/>
        <vers num="snv_73" edition=":x86"/>
        <vers num="snv_73" edition=":sparc"/>
        <vers num="snv_74" edition=""/>
        <vers num="snv_74" edition=":sparc"/>
        <vers num="snv_74" edition=":x86"/>
        <vers num="snv_75" edition=""/>
        <vers num="snv_75" edition=":sparc"/>
        <vers num="snv_75" edition=":x86"/>
        <vers num="snv_76" edition=""/>
        <vers num="snv_76" edition=":x86"/>
        <vers num="snv_76" edition=":sparc"/>
        <vers num="snv_77" edition=""/>
        <vers num="snv_77" edition=":sparc"/>
        <vers num="snv_77" edition=":x86"/>
        <vers num="snv_78" edition=""/>
        <vers num="snv_78" edition=":sparc"/>
        <vers num="snv_78" edition=":x86"/>
        <vers num="snv_79" edition=""/>
        <vers num="snv_79" edition=":x86"/>
        <vers num="snv_79" edition=":sparc"/>
        <vers num="snv_80" edition=""/>
        <vers num="snv_80" edition=":x86"/>
        <vers num="snv_80" edition=":sparc"/>
        <vers num="snv_81" edition=""/>
        <vers num="snv_81" edition=":x86"/>
        <vers num="snv_81" edition=":sparc"/>
        <vers num="snv_82" edition=""/>
        <vers num="snv_82" edition=":x86"/>
        <vers num="snv_82" edition=":sparc"/>
        <vers num="snv_83" edition=""/>
        <vers num="snv_83" edition=":x86"/>
        <vers num="snv_83" edition=":sparc"/>
        <vers num="snv_84" edition=""/>
        <vers num="snv_84" edition=":x86"/>
        <vers num="snv_84" edition=":sparc"/>
        <vers num="snv_85" edition=""/>
        <vers num="snv_85" edition=":x86"/>
        <vers num="snv_85" edition=":sparc"/>
        <vers num="snv_86" edition=""/>
        <vers num="snv_86" edition=":sparc"/>
        <vers num="snv_86" edition=":x86"/>
        <vers num="snv_87" edition=""/>
        <vers num="snv_87" edition=":sparc"/>
        <vers num="snv_87" edition=":x86"/>
        <vers num="snv_88" edition=""/>
        <vers num="snv_88" edition=":x86"/>
        <vers num="snv_88" edition=":sparc"/>
        <vers num="snv_89" edition=""/>
        <vers num="snv_89" edition=":x86"/>
        <vers num="snv_89" edition=":sparc"/>
        <vers num="snv_90" edition=""/>
        <vers num="snv_90" edition=":sparc"/>
        <vers num="snv_90" edition=":x86"/>
        <vers num="snv_91" edition=""/>
        <vers num="snv_91" edition=":sparc"/>
        <vers num="snv_91" edition=":x86"/>
        <vers num="snv_92" edition=""/>
        <vers num="snv_92" edition=":sparc"/>
        <vers num="snv_92" edition=":x86"/>
        <vers num="snv_93" edition=""/>
        <vers num="snv_93" edition=":sparc"/>
        <vers num="snv_93" edition=":x86"/>
        <vers num="snv_94" edition=""/>
        <vers num="snv_94" edition=":x86"/>
        <vers num="snv_94" edition=":sparc"/>
        <vers num="snv_95" edition=""/>
        <vers num="snv_95" edition=":x86"/>
        <vers num="snv_95" edition=":sparc"/>
        <vers num="snv_96" edition=""/>
        <vers num="snv_96" edition=":sparc"/>
        <vers num="snv_96" edition=":x86"/>
        <vers num="snv_97" edition=""/>
        <vers num="snv_97" edition=":x86"/>
        <vers num="snv_97" edition=":sparc"/>
        <vers num="snv_98" edition=""/>
        <vers num="snv_98" edition=":sparc"/>
        <vers num="snv_98" edition=":x86"/>
        <vers num="snv_99" edition=""/>
        <vers num="snv_99" edition=":sparc"/>
        <vers num="snv_99" edition=":x86"/>
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10" edition=""/>
        <vers num="10" edition=":sparc"/>
        <vers num="10" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0305" published="2009-02-10" name="CVE-2009-0305" modified="2009-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the Research in Motion RIM AxLoader ActiveX control in AxLoader.ocx and AxLoader.dll in BlackBerry Application Web Loader 1.0 allow remote attackers to execute arbitrary code via unspecified use of the (1) load or (2) loadJad method.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/131100" source="CERT-VN">VU#131100</ref>
      <ref url="http://blackberry.com/btsc/KB16248" source="CONFIRM" patch="1" adv="1">http://blackberry.com/btsc/KB16248</ref>
      <ref url="http://www.securityfocus.com/bid/33663" source="BID">33663</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/960715.mspx" source="CONFIRM">http://www.microsoft.com/technet/security/advisory/960715.mspx</ref>
      <ref url="http://secunia.com/advisories/33847" source="SECUNIA" adv="1">33847</ref>
      <ref url="http://osvdb.org/51833" source="OSVDB">51833</ref>
    </refs>
    <vuln_soft>
      <prod vendor="research_in_motion_limited" name="blackberry_application_web_loader">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0306" published="2009-11-04" name="CVE-2009-0306" modified="2009-11-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in the IBM Lotus Notes Intellisync ActiveX control in lnresobject.dll in BlackBerry Desktop Manager in Research In Motion (RIM) BlackBerry Desktop Software before 5.0.1 allows remote attackers to execute arbitrary code via a crafted web page.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/3133" source="VUPEN" patch="1" adv="1">ADV-2009-3133</ref>
      <ref url="http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB19701" source="CONFIRM" patch="1" adv="1">http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB19701</ref>
      <ref url="http://www.securityfocus.com/bid/36903" source="BID">36903</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_notes_intellisync">
        <vers num=""/>
      </prod>
      <prod vendor="rim" name="blackberry_desktop_software">
        <vers prev="1" num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0307" published="2009-04-22" name="CVE-2009-0307" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the "Customize Statistics Page" (admin/statistics/ConfigureStatistics) in the MDS Connection Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) before 4.1.6 MR5 allows remote attackers to inject arbitrary web script or HTML via the (1) customDate, (2) interval, (3) lastCustomInterval, (4) lastIntervalLength, (5) nextCustomInterval, (6) nextIntervalLength, (7) action, (8) delIntervalIndex, (9) addStatIndex, (10) delStatIndex, and (11) referenceTime parameters.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1090" source="VUPEN">ADV-2009-1090</ref>
      <ref url="http://www.securitytracker.com/id?1022081" source="SECTRACK">1022081</ref>
      <ref url="http://www.securityfocus.com/bid/34573" source="BID">34573</ref>
      <ref url="http://www.blackberry.com/btsc/dynamickc.do?externalId=KB17969&amp;sliceID=1&amp;command=show&amp;forward=nonthreadedKC&amp;kcId=KB17969" source="CONFIRM" adv="1">http://www.blackberry.com/btsc/dynamickc.do?externalId=KB17969&amp;sliceID=1&amp;command=show&amp;forward=nonthreadedKC&amp;kcId=KB17969</ref>
      <ref url="http://secunia.com/advisories/34740" source="SECUNIA" adv="1">34740</ref>
      <ref url="http://osvdb.org/53772" source="OSVDB">53772</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-04/0170.html" source="FULLDISC">20090417 ERNW Security Advisory 01-2009: XSS in Blackberries Mobile Data Service Connection Service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rim" name="blackberry_enterprise_server">
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0.3"/>
        <vers num="4.1" edition="sp3"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers prev="1" num="4.1.6" edition="mr4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0310" published="2009-02-18" name="CVE-2009-0310" modified="2009-03-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in SUSE blinux (aka sbl) in SUSE openSUSE 10.3 through 11.0 has unknown impact and attack vectors related to "incoming data and authentication-strings."</descript>
      <descript source="nvd">Following information confirms LOCAL Access Vector reported in Hyperlink Record 1058524:

http://xforce.iss.net/xforce/xfdb/48797

The SUSE blinux (sbl) package is vulnerable to a buffer overflow. By sending a specially-crafted request, a local attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48797" source="XF">suse-blinux-bo(48797)</ref>
      <ref url="http://www.securityfocus.com/bid/33794" source="BID">33794</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html" source="SUSE" adv="1">SUSE-SR:2009:004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="opensuse">
        <vers num="10.3"/>
        <vers num="11.0"/>
      </prod>
      <prod vendor="opensuse" name="opensuse">
        <vers num="10.3"/>
        <vers num="11.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0311" published="2009-01-27" name="CVE-2009-0311" modified="2009-01-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Backbone service (ftbackbone.exe) in EMC AutoStart before 5.3 SP2 allows remote attackers to execute arbitrary code via a packet with a crafted value that is dereferenced as a function pointer.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://zerodayinitiative.com/advisories/ZDI-09-009/" source="MISC">http://zerodayinitiative.com/advisories/ZDI-09-009/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48197" source="XF">autostart-backbone-code-execution(48197)</ref>
      <ref url="http://www.securitytracker.com/id?1021636" source="SECTRACK">1021636</ref>
      <ref url="http://www.securityfocus.com/bid/33415" source="BID">33415</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500350/100/0/threaded" source="BUGTRAQ">20090123 ZDI-09-009: EMC AutoStart Backbone Engine Trusted Pointer Code Execution Vulnerability</ref>
      <ref url="http://secunia.com/advisories/33667" source="SECUNIA" adv="1">33667</ref>
      <ref url="http://osvdb.org/51566" source="OSVDB">51566</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emc" name="autostart">
        <vers prev="1" num="5.3" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0312" published="2009-01-27" name="CVE-2009-0312" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the antispam feature (security/antispam.py) in MoinMoin 1.7 and 1.8.1 allows remote attackers to inject arbitrary web script or HTML via crafted, disallowed content.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48306" source="XF">moinmoin-antispam-xss(48306)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-716-1" source="UBUNTU">USN-716-1</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/27/4" source="MLIST">[oss-security] 20090127 CVE Request: MoinMoin</ref>
      <ref url="http://secunia.com/advisories/33755" source="SECUNIA">33755</ref>
      <ref url="http://secunia.com/advisories/33716" source="SECUNIA">33716</ref>
      <ref url="http://osvdb.org/51632" source="OSVDB">51632</ref>
      <ref url="http://moinmo.in/SecurityFixes#moin1.8.1" source="CONFIRM" adv="1">http://moinmo.in/SecurityFixes#moin1.8.1</ref>
      <ref url="http://lists.debian.org/debian-security-announce/2009/msg00023.html" source="DEBIAN">DSA-1715</ref>
      <ref url="http://hg.moinmo.in/moin/1.8/rev/89b91bf87dad" source="CONFIRM">http://hg.moinmo.in/moin/1.8/rev/89b91bf87dad</ref>
      <ref url="http://hg.moinmo.in/moin/1.7/rev/89b91bf87dad" source="CONFIRM">http://hg.moinmo.in/moin/1.7/rev/89b91bf87dad</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moinmoin" name="moinmoin">
        <vers num="1.7.0"/>
        <vers num="1.8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0313" published="2009-01-27" name="CVE-2009-0313" modified="2009-02-20" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">winetricks before 20081223 allows local users to overwrite arbitrary files via a symlink attack on the x_showmenu.txt temporary file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48320" source="XF">winetricks-xshowmenu-symlink(48320)</ref>
      <ref url="http://www.securityfocus.com/bid/33474" source="BID">33474</ref>
      <ref url="http://osvdb.org/51619" source="OSVDB">51619</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html" source="SUSE">SUSE-SR:2009:004</ref>
      <ref url="http://code.google.com/p/winezeug/source/detail?r=253" source="CONFIRM">http://code.google.com/p/winezeug/source/detail?r=253</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kegel" name="winetricks">
        <vers num="20081127"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0314" published="2009-01-28" name="CVE-2009-0314" modified="2011-09-12" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in the Python module in gedit allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg01195.html" source="FEDORA">FEDORA-2009-1189</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=481556" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=481556</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48271" source="XF">gedit-pysyssetargv-privilege-escalation(48271)</ref>
      <ref url="http://www.securityfocus.com/bid/33445" source="BID">33445</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/26/2" source="MLIST">[oss-security] 20090126 CVE request -- Python &lt; 2.6 PySys_SetArgv issues (epiphany, csound, dia, eog, gedit, xchat, vim, nautilus-python, Gnumeric)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:039" source="MANDRIVA">MDVSA-2009:039</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200903-41.xml" source="GENTOO">GLSA-200903-41</ref>
      <ref url="http://secunia.com/advisories/34522" source="SECUNIA">34522</ref>
      <ref url="http://secunia.com/advisories/33769" source="SECUNIA">33769</ref>
      <ref url="http://secunia.com/advisories/33759" source="SECUNIA">33759</ref>
      <ref url="http://bugzilla.gnome.org/show_bug.cgi?id=569214" source="MISC">http://bugzilla.gnome.org/show_bug.cgi?id=569214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gedit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0315" published="2009-01-28" name="CVE-2009-0315" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in the Python module in xchat allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=481560" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=481560</ref>
      <ref url="http://www.securityfocus.com/bid/33444" source="BID">33444</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/26/2" source="MLIST">[oss-security] 20090126 CVE request -- Python &lt; 2.6 PySys_SetArgv issues (epiphany, csound, dia, eog, gedit, xchat, vim, nautilus-python, Gnumeric)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:059" source="MANDRIVA">MDVSA-2009:059</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xchat" name="xchat">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0316" published="2009-01-28" name="CVE-2009-0316" modified="2010-04-01" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in src/if_python.c in the Python interface in Vim before 7.2.045 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983), as demonstrated by an erroneous search path for plugin/bike.vim in bicyclerepair.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://svn.pardus.org.tr/pardus/2008/applications/editors/vim/files/official/7.2.045" source="CONFIRM">https://svn.pardus.org.tr/pardus/2008/applications/editors/vim/files/official/7.2.045</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=481565" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=481565</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48275" source="XF">vim-pysyssetargv-privilege-escalation(48275)</ref>
      <ref url="http://www.securityfocus.com/bid/33447" source="BID">33447</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/26/2" source="MLIST">[oss-security] 20090126 CVE request -- Python &lt; 2.6 PySys_SetArgv issues (epiphany, csound, dia, eog, gedit, xchat, vim, nautilus-python, Gnumeric)</ref>
      <ref url="http://www.nabble.com/Bug-484305%3A-bicyclerepair%3A-bike.vim-imports-untrusted-python-files-from-cwd-td18848099.html" source="MLIST">[debian-bugs-rc] 20080805 Bug#484305: bicyclerepair: bike.vim imports untrusted python files from cwd</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:047" source="MANDRIVA">MDVSA-2009:047</ref>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE">APPLE-SA-2010-03-29-1</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=493937" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=493937</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=484305" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=484305</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vim" name="vim">
        <vers num="1.0"/>
        <vers num="1.22"/>
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.6"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers prev="1" num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0317" published="2009-01-28" name="CVE-2009-0317" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in the Python language bindings for Nautilus (nautilus-python) allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=481570" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=481570</ref>
      <ref url="http://www.securityfocus.com/bid/33442" source="BID">33442</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/26/2" source="MLIST">[oss-security] 20090126 CVE request -- Python &lt; 2.6 PySys_SetArgv issues (epiphany, csound, dia, eog, gedit, xchat, vim, nautilus-python, Gnumeric)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="nautilus-python">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0318" published="2009-01-28" name="CVE-2009-0318" modified="2009-04-16" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00211.html" source="FEDORA">FEDORA-2009-1295</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=481572" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=481572</ref>
      <ref url="http://www.securityfocus.com/bid/33438" source="BID">33438</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/26/2" source="MLIST">[oss-security] 20090126 CVE request -- Python &lt; 2.6 PySys_SetArgv issues (epiphany, csound, dia, eog, gedit, xchat, vim, nautilus-python, Gnumeric)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:043" source="MANDRIVA">MDVSA-2009:043</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-03.xml" source="GENTOO">GLSA-200904-03</ref>
      <ref url="http://secunia.com/advisories/33823" source="SECUNIA">33823</ref>
      <ref url="http://secunia.com/advisories/33707" source="SECUNIA">33707</ref>
      <ref url="http://bugzilla.gnome.org/show_bug.cgi?id=569648" source="CONFIRM">http://bugzilla.gnome.org/show_bug.cgi?id=569648</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gnumeric">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0319" published="2009-01-28" name="CVE-2009-0319" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in the autofs module in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_108, allows local users to cause a denial of service (autofs mount outage) or possibly gain privileges via vectors related to "xdr processing problems."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-249966-1" source="SUNALERT" patch="1" adv="1">249966</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-128624-09-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-128624-09-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48234" source="XF">solaris-autofs-code-execution(48234)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0363" source="VUPEN">ADV-2009-0363</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0256" source="VUPEN">ADV-2009-0256</ref>
      <ref url="http://www.securitytracker.com/id?1021644" source="SECTRACK">1021644</ref>
      <ref url="http://www.securityfocus.com/bid/33459" source="BID">33459</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-041.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-041.htm</ref>
      <ref url="http://secunia.com/advisories/33665" source="SECUNIA">33665</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5977" source="OVAL">oval:org.mitre.oval:def:5977</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_01" edition=""/>
        <vers num="snv_01" edition=":sparc"/>
        <vers num="snv_01" edition=":x86"/>
        <vers num="snv_02" edition=""/>
        <vers num="snv_02" edition=":sparc"/>
        <vers num="snv_02" edition=":x86"/>
        <vers num="snv_03" edition=""/>
        <vers num="snv_03" edition=":x86"/>
        <vers num="snv_03" edition=":sparc"/>
        <vers num="snv_04" edition=""/>
        <vers num="snv_04" edition=":x86"/>
        <vers num="snv_04" edition=":sparc"/>
        <vers num="snv_05" edition=""/>
        <vers num="snv_05" edition=":sparc"/>
        <vers num="snv_05" edition=":x86"/>
        <vers num="snv_06" edition=""/>
        <vers num="snv_06" edition=":sparc"/>
        <vers num="snv_06" edition=":x86"/>
        <vers num="snv_07" edition=""/>
        <vers num="snv_07" edition=":sparc"/>
        <vers num="snv_07" edition=":x86"/>
        <vers num="snv_08" edition=""/>
        <vers num="snv_08" edition=":x86"/>
        <vers num="snv_08" edition=":sparc"/>
        <vers num="snv_09" edition=""/>
        <vers num="snv_09" edition=":x86"/>
        <vers num="snv_09" edition=":sparc"/>
        <vers num="snv_10" edition=""/>
        <vers num="snv_10" edition=":x86"/>
        <vers num="snv_10" edition=":sparc"/>
        <vers num="snv_100" edition=""/>
        <vers num="snv_100" edition=":sparc"/>
        <vers num="snv_100" edition=":x86"/>
        <vers num="snv_101" edition=""/>
        <vers num="snv_101" edition=":x86"/>
        <vers num="snv_101" edition=":sparc"/>
        <vers num="snv_102" edition=""/>
        <vers num="snv_102" edition=":sparc"/>
        <vers num="snv_102" edition=":x86"/>
        <vers num="snv_103" edition=""/>
        <vers num="snv_103" edition=":x86"/>
        <vers num="snv_103" edition=":sparc"/>
        <vers num="snv_104" edition=""/>
        <vers num="snv_104" edition=":x86"/>
        <vers num="snv_104" edition=":sparc"/>
        <vers num="snv_105" edition=""/>
        <vers num="snv_105" edition=":x86"/>
        <vers num="snv_105" edition=":sparc"/>
        <vers num="snv_106" edition=""/>
        <vers num="snv_106" edition=":sparc"/>
        <vers num="snv_106" edition=":x86"/>
        <vers prev="1" num="snv_107" edition=""/>
        <vers prev="1" num="snv_107" edition=":x86"/>
        <vers prev="1" num="snv_107" edition=":sparc"/>
        <vers num="snv_11" edition=""/>
        <vers num="snv_11" edition=":sparc"/>
        <vers num="snv_12" edition=""/>
        <vers num="snv_12" edition=":sparc"/>
        <vers num="snv_13" edition=""/>
        <vers num="snv_13" edition=":sparc"/>
        <vers num="snv_14" edition=""/>
        <vers num="snv_14" edition=":sparc"/>
        <vers num="snv_15" edition=""/>
        <vers num="snv_15" edition=":sparc"/>
        <vers num="snv_16" edition=""/>
        <vers num="snv_16" edition=":sparc"/>
        <vers num="snv_17" edition=""/>
        <vers num="snv_17" edition=":sparc"/>
        <vers num="snv_18" edition=""/>
        <vers num="snv_18" edition=":sparc"/>
        <vers num="snv_19" edition=""/>
        <vers num="snv_19" edition=":sparc"/>
        <vers num="snv_20" edition=""/>
        <vers num="snv_20" edition=":sparc"/>
        <vers num="snv_21" edition=""/>
        <vers num="snv_21" edition=":sparc"/>
        <vers num="snv_21" edition=":x86"/>
        <vers num="snv_22" edition=""/>
        <vers num="snv_22" edition=":sparc"/>
        <vers num="snv_22" edition=":x86"/>
        <vers num="snv_23" edition=""/>
        <vers num="snv_23" edition=":sparc"/>
        <vers num="snv_23" edition=":x86"/>
        <vers num="snv_24" edition=""/>
        <vers num="snv_24" edition=":sparc"/>
        <vers num="snv_24" edition=":x86"/>
        <vers num="snv_25" edition=""/>
        <vers num="snv_25" edition=":x86"/>
        <vers num="snv_25" edition=":sparc"/>
        <vers num="snv_26" edition=""/>
        <vers num="snv_26" edition=":x86"/>
        <vers num="snv_26" edition=":sparc"/>
        <vers num="snv_27" edition=""/>
        <vers num="snv_27" edition=":sparc"/>
        <vers num="snv_27" edition=":x86"/>
        <vers num="snv_28" edition=""/>
        <vers num="snv_28" edition=":x86"/>
        <vers num="snv_28" edition=":sparc"/>
        <vers num="snv_29" edition=""/>
        <vers num="snv_29" edition=":x86"/>
        <vers num="snv_29" edition=":sparc"/>
        <vers num="snv_30" edition=""/>
        <vers num="snv_30" edition=":sparc"/>
        <vers num="snv_30" edition=":x86"/>
        <vers num="snv_31" edition=""/>
        <vers num="snv_31" edition=":sparc"/>
        <vers num="snv_31" edition=":x86"/>
        <vers num="snv_32" edition=""/>
        <vers num="snv_32" edition=":x86"/>
        <vers num="snv_32" edition=":sparc"/>
        <vers num="snv_33" edition=""/>
        <vers num="snv_33" edition=":x86"/>
        <vers num="snv_33" edition=":sparc"/>
        <vers num="snv_34" edition=""/>
        <vers num="snv_34" edition=":sparc"/>
        <vers num="snv_34" edition=":x86"/>
        <vers num="snv_35" edition=""/>
        <vers num="snv_35" edition=":sparc"/>
        <vers num="snv_35" edition=":x86"/>
        <vers num="snv_36" edition=""/>
        <vers num="snv_36" edition=":x86"/>
        <vers num="snv_36" edition=":sparc"/>
        <vers num="snv_37" edition=""/>
        <vers num="snv_37" edition=":sparc"/>
        <vers num="snv_37" edition=":x86"/>
        <vers num="snv_38" edition=""/>
        <vers num="snv_38" edition=":sparc"/>
        <vers num="snv_38" edition=":x86"/>
        <vers num="snv_39" edition=""/>
        <vers num="snv_39" edition=":sparc"/>
        <vers num="snv_39" edition=":x86"/>
        <vers num="snv_40" edition=""/>
        <vers num="snv_40" edition=":sparc"/>
        <vers num="snv_40" edition=":x86"/>
        <vers num="snv_41" edition=""/>
        <vers num="snv_41" edition=":sparc"/>
        <vers num="snv_41" edition=":x86"/>
        <vers num="snv_42" edition=""/>
        <vers num="snv_42" edition=":x86"/>
        <vers num="snv_42" edition=":sparc"/>
        <vers num="snv_43" edition=""/>
        <vers num="snv_43" edition=":sparc"/>
        <vers num="snv_43" edition=":x86"/>
        <vers num="snv_44" edition=""/>
        <vers num="snv_44" edition=":x86"/>
        <vers num="snv_44" edition=":sparc"/>
        <vers num="snv_45" edition=""/>
        <vers num="snv_45" edition=":x86"/>
        <vers num="snv_45" edition=":sparc"/>
        <vers num="snv_46" edition=""/>
        <vers num="snv_46" edition=":x86"/>
        <vers num="snv_46" edition=":sparc"/>
        <vers num="snv_47" edition=""/>
        <vers num="snv_47" edition=":x86"/>
        <vers num="snv_47" edition=":sparc"/>
        <vers num="snv_48" edition=""/>
        <vers num="snv_48" edition=":sparc"/>
        <vers num="snv_48" edition=":x86"/>
        <vers num="snv_49" edition=""/>
        <vers num="snv_49" edition=":sparc"/>
        <vers num="snv_49" edition=":x86"/>
        <vers num="snv_50" edition=""/>
        <vers num="snv_50" edition=":sparc"/>
        <vers num="snv_50" edition=":x86"/>
        <vers num="snv_51" edition=""/>
        <vers num="snv_51" edition=":sparc"/>
        <vers num="snv_51" edition=":x86"/>
        <vers num="snv_52" edition=""/>
        <vers num="snv_52" edition=":sparc"/>
        <vers num="snv_52" edition=":x86"/>
        <vers num="snv_53" edition=""/>
        <vers num="snv_53" edition=":sparc"/>
        <vers num="snv_53" edition=":x86"/>
        <vers num="snv_54" edition=""/>
        <vers num="snv_54" edition=":x86"/>
        <vers num="snv_54" edition=":sparc"/>
        <vers num="snv_55" edition=""/>
        <vers num="snv_55" edition=":sparc"/>
        <vers num="snv_55" edition=":x86"/>
        <vers num="snv_56" edition=""/>
        <vers num="snv_56" edition=":x86"/>
        <vers num="snv_56" edition=":sparc"/>
        <vers num="snv_57" edition=""/>
        <vers num="snv_57" edition=":x86"/>
        <vers num="snv_57" edition=":sparc"/>
        <vers num="snv_58" edition=""/>
        <vers num="snv_58" edition=":sparc"/>
        <vers num="snv_58" edition=":x86"/>
        <vers num="snv_59" edition=""/>
        <vers num="snv_59" edition=":sparc"/>
        <vers num="snv_59" edition=":x86"/>
        <vers num="snv_60" edition=""/>
        <vers num="snv_60" edition=":x86"/>
        <vers num="snv_60" edition=":sparc"/>
        <vers num="snv_61" edition=""/>
        <vers num="snv_61" edition=":sparc"/>
        <vers num="snv_61" edition=":x86"/>
        <vers num="snv_62" edition=""/>
        <vers num="snv_62" edition=":x86"/>
        <vers num="snv_62" edition=":sparc"/>
        <vers num="snv_63" edition=""/>
        <vers num="snv_63" edition=":sparc"/>
        <vers num="snv_63" edition=":x86"/>
        <vers num="snv_64" edition=""/>
        <vers num="snv_64" edition=":x86"/>
        <vers num="snv_64" edition=":sparc"/>
        <vers num="snv_65" edition=""/>
        <vers num="snv_65" edition=":x86"/>
        <vers num="snv_65" edition=":sparc"/>
        <vers num="snv_66" edition=""/>
        <vers num="snv_66" edition=":x86"/>
        <vers num="snv_66" edition=":sparc"/>
        <vers num="snv_67" edition=""/>
        <vers num="snv_67" edition=":sparc"/>
        <vers num="snv_67" edition=":x86"/>
        <vers num="snv_68" edition=""/>
        <vers num="snv_68" edition=":x86"/>
        <vers num="snv_68" edition=":sparc"/>
        <vers num="snv_69" edition=""/>
        <vers num="snv_69" edition=":sparc"/>
        <vers num="snv_69" edition=":x86"/>
        <vers num="snv_70" edition=""/>
        <vers num="snv_70" edition=":sparc"/>
        <vers num="snv_70" edition=":x86"/>
        <vers num="snv_71" edition=""/>
        <vers num="snv_71" edition=":x86"/>
        <vers num="snv_71" edition=":sparc"/>
        <vers num="snv_72" edition=""/>
        <vers num="snv_72" edition=":x86"/>
        <vers num="snv_72" edition=":sparc"/>
        <vers num="snv_73" edition=""/>
        <vers num="snv_73" edition=":x86"/>
        <vers num="snv_73" edition=":sparc"/>
        <vers num="snv_74" edition=""/>
        <vers num="snv_74" edition=":sparc"/>
        <vers num="snv_74" edition=":x86"/>
        <vers num="snv_75" edition=""/>
        <vers num="snv_75" edition=":sparc"/>
        <vers num="snv_75" edition=":x86"/>
        <vers num="snv_76" edition=""/>
        <vers num="snv_76" edition=":x86"/>
        <vers num="snv_76" edition=":sparc"/>
        <vers num="snv_77" edition=""/>
        <vers num="snv_77" edition=":sparc"/>
        <vers num="snv_77" edition=":x86"/>
        <vers num="snv_78" edition=""/>
        <vers num="snv_78" edition=":sparc"/>
        <vers num="snv_78" edition=":x86"/>
        <vers num="snv_79" edition=""/>
        <vers num="snv_79" edition=":x86"/>
        <vers num="snv_79" edition=":sparc"/>
        <vers num="snv_80" edition=""/>
        <vers num="snv_80" edition=":x86"/>
        <vers num="snv_80" edition=":sparc"/>
        <vers num="snv_81" edition=""/>
        <vers num="snv_81" edition=":x86"/>
        <vers num="snv_81" edition=":sparc"/>
        <vers num="snv_82" edition=""/>
        <vers num="snv_82" edition=":x86"/>
        <vers num="snv_82" edition=":sparc"/>
        <vers num="snv_83" edition=""/>
        <vers num="snv_83" edition=":x86"/>
        <vers num="snv_83" edition=":sparc"/>
        <vers num="snv_84" edition=""/>
        <vers num="snv_84" edition=":x86"/>
        <vers num="snv_84" edition=":sparc"/>
        <vers num="snv_85" edition=""/>
        <vers num="snv_85" edition=":x86"/>
        <vers num="snv_85" edition=":sparc"/>
        <vers num="snv_86" edition=""/>
        <vers num="snv_86" edition=":sparc"/>
        <vers num="snv_86" edition=":x86"/>
        <vers num="snv_87" edition=""/>
        <vers num="snv_87" edition=":sparc"/>
        <vers num="snv_87" edition=":x86"/>
        <vers num="snv_88" edition=""/>
        <vers num="snv_88" edition=":x86"/>
        <vers num="snv_88" edition=":sparc"/>
        <vers num="snv_89" edition=""/>
        <vers num="snv_89" edition=":x86"/>
        <vers num="snv_89" edition=":sparc"/>
        <vers num="snv_90" edition=""/>
        <vers num="snv_90" edition=":sparc"/>
        <vers num="snv_90" edition=":x86"/>
        <vers num="snv_91" edition=""/>
        <vers num="snv_91" edition=":sparc"/>
        <vers num="snv_91" edition=":x86"/>
        <vers num="snv_92" edition=""/>
        <vers num="snv_92" edition=":sparc"/>
        <vers num="snv_92" edition=":x86"/>
        <vers num="snv_93" edition=""/>
        <vers num="snv_93" edition=":sparc"/>
        <vers num="snv_93" edition=":x86"/>
        <vers num="snv_94" edition=""/>
        <vers num="snv_94" edition=":x86"/>
        <vers num="snv_94" edition=":sparc"/>
        <vers num="snv_95" edition=""/>
        <vers num="snv_95" edition=":x86"/>
        <vers num="snv_95" edition=":sparc"/>
        <vers num="snv_96" edition=""/>
        <vers num="snv_96" edition=":sparc"/>
        <vers num="snv_96" edition=":x86"/>
        <vers num="snv_97" edition=""/>
        <vers num="snv_97" edition=":x86"/>
        <vers num="snv_97" edition=":sparc"/>
        <vers num="snv_98" edition=""/>
        <vers num="snv_98" edition=":sparc"/>
        <vers num="snv_98" edition=":x86"/>
        <vers num="snv_99" edition=""/>
        <vers num="snv_99" edition=":sparc"/>
        <vers num="snv_99" edition=":x86"/>
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10" edition=""/>
        <vers num="10" edition=":sparc"/>
        <vers num="10" edition=":x86"/>
        <vers num="8" edition=""/>
        <vers num="8" edition=":sparc"/>
        <vers num="8" edition=":x86"/>
        <vers num="9" edition=""/>
        <vers num="9" edition=":x86"/>
        <vers num="9" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0320" published="2009-01-28" name="CVE-2009-0320" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="1.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Microsoft Windows XP, Server 2003 and 2008, and Vista exposes I/O activity measurements of all processes, which allows local users to obtain sensitive information, as demonstrated by reading the I/O Other Bytes column in Task Manager (aka taskmgr.exe) to estimate the number of characters that a different user entered at a runas.exe password prompt, related to a "benchmarking attack."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33440" source="BID">33440</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500393/100/0/threaded" source="BUGTRAQ">20090124 Benchmarking attacks and major security weakness on all recent Windows versions up to Windows 200</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0321" published="2009-01-28" name="CVE-2009-0321" modified="2009-03-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Apple Safari 3.2.1 (aka AppVer 3.525.27.1) on Windows allows remote attackers to cause a denial of service (infinite loop or access violation) via a link to an http URI in which the authority (aka hostname) portion is either a (1) . (dot) or (2) .. (dot dot) sequence.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48284" source="XF">safari-httpuri-dos(48284)</ref>
      <ref url="http://www.securityfocus.com/bid/33481" source="BID">33481</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6091" source="OVAL">oval:org.mitre.oval:def:6091</ref>
      <ref url="http://lostmon.blogspot.com/2009/01/safari-for-windows-321-remote-http-uri.html" source="MISC">http://lostmon.blogspot.com/2009/01/safari-for-windows-321-remote-http-uri.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="3.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0322" published="2009-01-28" name="CVE-2009-0322" modified="2012-03-19" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">drivers/firmware/dell_rbu.c in the Linux kernel before 2.6.27.13, and 2.6.28.x before 2.6.28.2, allows local users to cause a denial of service (system crash) via a read system call that specifies zero bytes from the (1) image_type or (2) packet_size file in /sys/devices/platform/dell_rbu/.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33428" source="BID" patch="1">33428</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-751-1" source="UBUNTU">USN-751-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0360.html" source="REDHAT">RHSA-2009:0360</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0331.html" source="REDHAT">RHSA-2009:0331</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0326.html" source="REDHAT">RHSA-2009:0326</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1794" source="DEBIAN">DSA-1794</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1787" source="DEBIAN">DSA-1787</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1749" source="DEBIAN">DSA-1749</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-114.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-114.htm</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA">37471</ref>
      <ref url="http://secunia.com/advisories/35394" source="SECUNIA">35394</ref>
      <ref url="http://secunia.com/advisories/35390" source="SECUNIA">35390</ref>
      <ref url="http://secunia.com/advisories/35011" source="SECUNIA">35011</ref>
      <ref url="http://secunia.com/advisories/34981" source="SECUNIA">34981</ref>
      <ref url="http://secunia.com/advisories/34762" source="SECUNIA">34762</ref>
      <ref url="http://secunia.com/advisories/34680" source="SECUNIA">34680</ref>
      <ref url="http://secunia.com/advisories/34502" source="SECUNIA">34502</ref>
      <ref url="http://secunia.com/advisories/34394" source="SECUNIA">34394</ref>
      <ref url="http://secunia.com/advisories/34252" source="SECUNIA">34252</ref>
      <ref url="http://secunia.com/advisories/33758" source="SECUNIA">33758</ref>
      <ref url="http://secunia.com/advisories/33656" source="SECUNIA" adv="1">33656</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7734" source="OVAL">oval:org.mitre.oval:def:7734</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10163" source="OVAL">oval:org.mitre.oval:def:10163</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE">SUSE-SA:2009:031</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE">SUSE-SA:2009:030</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.html" source="SUSE">SUSE-SA:2009:010</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.2" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.2</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.13" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.13</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git;a=commit;h=81156928f8fe31621e467490b9d441c0285998c3" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git;a=commit;h=81156928f8fe31621e467490b9d441c0285998c3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.10"/>
        <vers num="2.6.11"/>
        <vers num="2.6.11.1"/>
        <vers num="2.6.11.10"/>
        <vers num="2.6.11.11"/>
        <vers num="2.6.11.12"/>
        <vers num="2.6.11.2"/>
        <vers num="2.6.11.3"/>
        <vers num="2.6.11.4"/>
        <vers num="2.6.11.5"/>
        <vers num="2.6.11.6"/>
        <vers num="2.6.11.7"/>
        <vers num="2.6.11.8"/>
        <vers num="2.6.11.9"/>
        <vers num="2.6.12"/>
        <vers num="2.6.12.1"/>
        <vers num="2.6.12.2"/>
        <vers num="2.6.12.3"/>
        <vers num="2.6.12.4"/>
        <vers num="2.6.12.5"/>
        <vers num="2.6.12.6"/>
        <vers num="2.6.13"/>
        <vers num="2.6.13.1"/>
        <vers num="2.6.13.2"/>
        <vers num="2.6.13.3"/>
        <vers num="2.6.13.4"/>
        <vers num="2.6.13.5"/>
        <vers num="2.6.14"/>
        <vers num="2.6.14.1"/>
        <vers num="2.6.14.2"/>
        <vers num="2.6.14.3"/>
        <vers num="2.6.14.4"/>
        <vers num="2.6.14.5"/>
        <vers num="2.6.14.6"/>
        <vers num="2.6.14.7"/>
        <vers num="2.6.15"/>
        <vers num="2.6.15.1"/>
        <vers num="2.6.15.2"/>
        <vers num="2.6.15.3"/>
        <vers num="2.6.15.4"/>
        <vers num="2.6.15.5"/>
        <vers num="2.6.15.6"/>
        <vers num="2.6.15.7"/>
        <vers num="2.6.16"/>
        <vers num="2.6.16.1"/>
        <vers num="2.6.16.10"/>
        <vers num="2.6.16.11"/>
        <vers num="2.6.16.12"/>
        <vers num="2.6.16.13"/>
        <vers num="2.6.16.14"/>
        <vers num="2.6.16.15"/>
        <vers num="2.6.16.16"/>
        <vers num="2.6.16.17"/>
        <vers num="2.6.16.18"/>
        <vers num="2.6.16.19"/>
        <vers num="2.6.16.2"/>
        <vers num="2.6.16.20"/>
        <vers num="2.6.16.21"/>
        <vers num="2.6.16.22"/>
        <vers num="2.6.16.23"/>
        <vers num="2.6.16.24"/>
        <vers num="2.6.16.25"/>
        <vers num="2.6.16.26"/>
        <vers num="2.6.16.27"/>
        <vers num="2.6.16.28"/>
        <vers num="2.6.16.29"/>
        <vers num="2.6.16.3"/>
        <vers num="2.6.16.30"/>
        <vers num="2.6.16.31"/>
        <vers num="2.6.16.32"/>
        <vers num="2.6.16.33"/>
        <vers num="2.6.16.34"/>
        <vers num="2.6.16.35"/>
        <vers num="2.6.16.36"/>
        <vers num="2.6.16.37"/>
        <vers num="2.6.16.38"/>
        <vers num="2.6.16.39"/>
        <vers num="2.6.16.4"/>
        <vers num="2.6.16.40"/>
        <vers num="2.6.16.41"/>
        <vers num="2.6.16.42"/>
        <vers num="2.6.16.43"/>
        <vers num="2.6.16.44"/>
        <vers num="2.6.16.45"/>
        <vers num="2.6.16.46"/>
        <vers num="2.6.16.47"/>
        <vers num="2.6.16.48"/>
        <vers num="2.6.16.49"/>
        <vers num="2.6.16.5"/>
        <vers num="2.6.16.50"/>
        <vers num="2.6.16.51"/>
        <vers num="2.6.16.52"/>
        <vers num="2.6.16.53"/>
        <vers num="2.6.16.54"/>
        <vers num="2.6.16.55"/>
        <vers num="2.6.16.56"/>
        <vers num="2.6.16.57"/>
        <vers num="2.6.16.58"/>
        <vers num="2.6.16.59"/>
        <vers num="2.6.16.6"/>
        <vers num="2.6.16.60"/>
        <vers num="2.6.16.61"/>
        <vers num="2.6.16.62"/>
        <vers num="2.6.16.7"/>
        <vers num="2.6.16.8"/>
        <vers num="2.6.16.9"/>
        <vers num="2.6.17"/>
        <vers num="2.6.17.1"/>
        <vers num="2.6.17.10"/>
        <vers num="2.6.17.11"/>
        <vers num="2.6.17.12"/>
        <vers num="2.6.17.13"/>
        <vers num="2.6.17.14"/>
        <vers num="2.6.17.2"/>
        <vers num="2.6.17.3"/>
        <vers num="2.6.17.4"/>
        <vers num="2.6.17.5"/>
        <vers num="2.6.17.6"/>
        <vers num="2.6.17.7"/>
        <vers num="2.6.17.8"/>
        <vers num="2.6.17.9"/>
        <vers num="2.6.18" edition="rc1"/>
        <vers num="2.6.18" edition="rc2"/>
        <vers num="2.6.18" edition="rc3"/>
        <vers num="2.6.18" edition="rc4"/>
        <vers num="2.6.18" edition="rc5"/>
        <vers num="2.6.18" edition="rc6"/>
        <vers num="2.6.18" edition="rc7"/>
        <vers num="2.6.18.1"/>
        <vers num="2.6.18.2"/>
        <vers num="2.6.18.3"/>
        <vers num="2.6.18.4"/>
        <vers num="2.6.18.5"/>
        <vers num="2.6.18.6"/>
        <vers num="2.6.18.7"/>
        <vers num="2.6.18.8"/>
        <vers num="2.6.19"/>
        <vers num="2.6.19.1"/>
        <vers num="2.6.19.2"/>
        <vers num="2.6.19.3"/>
        <vers num="2.6.19.4"/>
        <vers num="2.6.19.5"/>
        <vers num="2.6.19.6"/>
        <vers num="2.6.19.7"/>
        <vers num="2.6.2"/>
        <vers num="2.6.20"/>
        <vers num="2.6.20.1"/>
        <vers num="2.6.20.10"/>
        <vers num="2.6.20.11"/>
        <vers num="2.6.20.12"/>
        <vers num="2.6.20.13"/>
        <vers num="2.6.20.14"/>
        <vers num="2.6.20.15"/>
        <vers num="2.6.20.16"/>
        <vers num="2.6.20.17"/>
        <vers num="2.6.20.18"/>
        <vers num="2.6.20.19"/>
        <vers num="2.6.20.2"/>
        <vers num="2.6.20.20"/>
        <vers num="2.6.20.21"/>
        <vers num="2.6.20.3"/>
        <vers num="2.6.20.4"/>
        <vers num="2.6.20.5"/>
        <vers num="2.6.20.6"/>
        <vers num="2.6.20.7"/>
        <vers num="2.6.20.8"/>
        <vers num="2.6.20.9"/>
        <vers num="2.6.21"/>
        <vers num="2.6.21.1"/>
        <vers num="2.6.21.2"/>
        <vers num="2.6.21.3"/>
        <vers num="2.6.21.4"/>
        <vers num="2.6.21.5"/>
        <vers num="2.6.21.6"/>
        <vers num="2.6.21.7"/>
        <vers num="2.6.22"/>
        <vers num="2.6.22.1"/>
        <vers num="2.6.22.10"/>
        <vers num="2.6.22.11"/>
        <vers num="2.6.22.12"/>
        <vers num="2.6.22.13"/>
        <vers num="2.6.22.14"/>
        <vers num="2.6.22.15"/>
        <vers num="2.6.22.16"/>
        <vers num="2.6.22.17"/>
        <vers num="2.6.22.18"/>
        <vers num="2.6.22.19"/>
        <vers num="2.6.22.2"/>
        <vers num="2.6.22.20"/>
        <vers num="2.6.22.21"/>
        <vers num="2.6.22.22"/>
        <vers num="2.6.22.3"/>
        <vers num="2.6.22.4"/>
        <vers num="2.6.22.5"/>
        <vers num="2.6.22.6"/>
        <vers num="2.6.22.7"/>
        <vers num="2.6.22.8"/>
        <vers num="2.6.22.9"/>
        <vers num="2.6.23" edition="rc1"/>
        <vers num="2.6.23" edition="rc2"/>
        <vers num="2.6.23.1"/>
        <vers num="2.6.23.10"/>
        <vers num="2.6.23.11"/>
        <vers num="2.6.23.12"/>
        <vers num="2.6.23.13"/>
        <vers num="2.6.23.14"/>
        <vers num="2.6.23.15"/>
        <vers num="2.6.23.16"/>
        <vers num="2.6.23.17"/>
        <vers num="2.6.23.2"/>
        <vers num="2.6.23.3"/>
        <vers num="2.6.23.4"/>
        <vers num="2.6.23.5"/>
        <vers num="2.6.23.6"/>
        <vers num="2.6.23.7"/>
        <vers num="2.6.23.8"/>
        <vers num="2.6.23.9"/>
        <vers num="2.6.24" edition="rc1"/>
        <vers num="2.6.24" edition="rc2"/>
        <vers num="2.6.24" edition="rc3"/>
        <vers num="2.6.24" edition="rc4"/>
        <vers num="2.6.24" edition="rc5"/>
        <vers num="2.6.24.1"/>
        <vers num="2.6.24.2"/>
        <vers num="2.6.24.3"/>
        <vers num="2.6.24.4"/>
        <vers num="2.6.24.5"/>
        <vers num="2.6.24.6"/>
        <vers num="2.6.24.7"/>
        <vers num="2.6.25"/>
        <vers num="2.6.25.1"/>
        <vers num="2.6.25.10"/>
        <vers num="2.6.25.11"/>
        <vers num="2.6.25.12"/>
        <vers num="2.6.25.13"/>
        <vers num="2.6.25.14"/>
        <vers num="2.6.25.15"/>
        <vers num="2.6.25.16"/>
        <vers num="2.6.25.17"/>
        <vers num="2.6.25.18"/>
        <vers num="2.6.25.19"/>
        <vers num="2.6.25.2"/>
        <vers num="2.6.25.20"/>
        <vers num="2.6.25.3"/>
        <vers num="2.6.25.4"/>
        <vers num="2.6.25.5"/>
        <vers num="2.6.25.6"/>
        <vers num="2.6.25.7"/>
        <vers num="2.6.25.8"/>
        <vers num="2.6.25.9"/>
        <vers num="2.6.26"/>
        <vers num="2.6.26.1"/>
        <vers num="2.6.26.2"/>
        <vers num="2.6.26.3"/>
        <vers num="2.6.26.4"/>
        <vers num="2.6.26.5"/>
        <vers num="2.6.26.6"/>
        <vers num="2.6.26.7"/>
        <vers num="2.6.26.8"/>
        <vers num="2.6.27"/>
        <vers num="2.6.27.1"/>
        <vers num="2.6.27.10"/>
        <vers num="2.6.27.11"/>
        <vers prev="1" num="2.6.27.12"/>
        <vers num="2.6.27.2"/>
        <vers num="2.6.27.3"/>
        <vers num="2.6.27.4"/>
        <vers num="2.6.27.5"/>
        <vers num="2.6.27.6"/>
        <vers num="2.6.27.7"/>
        <vers num="2.6.27.8"/>
        <vers num="2.6.27.9"/>
        <vers num="2.6.28"/>
        <vers prev="1" num="2.6.28.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0323" published="2009-01-28" name="CVE-2009-0323" modified="2009-02-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0 and 11.0 allow remote attackers to execute arbitrary code via (1) a long type parameter in an input tag, which is not properly handled by the EndOfXmlAttributeValue function; (2) an "HTML GI" in a start tag, which is not properly handled by the ProcessStartGI function; and unspecified vectors in (3) html2thot.c and (4) xml2thot.c, related to the msgBuffer variable.  NOTE: these are different vectors than CVE-2008-6005.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48325" source="XF">amaya-html-tags-bo(48325)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500492/100/0/threaded" source="BUGTRAQ">20090128 CORE-2008-1211: Amaya web editor XML and HTML parser vulnerabilities</ref>
      <ref url="http://www.milw0rm.com/exploits/7902" source="MILW0RM">7902</ref>
      <ref url="http://www.coresecurity.com/content/amaya-buffer-overflows" source="MISC">http://www.coresecurity.com/content/amaya-buffer-overflows</ref>
    </refs>
    <vuln_soft>
      <prod vendor="w3" name="amaya">
        <vers num="0.9"/>
        <vers num="0.95b"/>
        <vers num="1.0"/>
        <vers num="1.0a"/>
        <vers num="1.1"/>
        <vers num="1.1a"/>
        <vers num="1.1c"/>
        <vers num="1.2"/>
        <vers num="1.2a"/>
        <vers num="1.3"/>
        <vers num="1.3a"/>
        <vers num="1.3b"/>
        <vers num="1.4"/>
        <vers num="1.4a"/>
        <vers num="10.0"/>
        <vers prev="1" num="11.0"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.2.1"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="8.0"/>
        <vers num="8.1"/>
        <vers num="8.1a"/>
        <vers num="8.1b"/>
        <vers num="8.2"/>
        <vers num="8.3"/>
        <vers num="8.4"/>
        <vers num="8.5"/>
        <vers num="8.52"/>
        <vers num="8.6"/>
        <vers num="8.7"/>
        <vers num="8.7.1"/>
        <vers num="8.7.2"/>
        <vers num="8.8.1"/>
        <vers num="8.8.3"/>
        <vers num="8.8.4"/>
        <vers num="8.8.5"/>
        <vers num="9.0"/>
        <vers num="9.1"/>
        <vers num="9.2.1"/>
        <vers num="9.3"/>
        <vers num="9.4"/>
        <vers num="9.5"/>
        <vers num="9.52"/>
        <vers num="9.53"/>
        <vers num="9.54"/>
        <vers num="9.55"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0324" published="2009-01-29" name="CVE-2009-0324" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in BibCiter 1.4 allow remote attackers to execute arbitrary SQL commands via the (1) idp parameter to reports/projects.php, the (2) idc parameter to reports/contacts.php, and the (3) idu parameter to reports/users.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48080" source="XF">bibciter-projects-sql-injection(48080)</ref>
      <ref url="http://www.securityfocus.com/bid/33329" source="BID">33329</ref>
      <ref url="http://www.milw0rm.com/exploits/7814" source="MILW0RM">7814</ref>
      <ref url="http://secunia.com/advisories/33555" source="SECUNIA" adv="1">33555</ref>
      <ref url="http://bibciter.sourceforge.net/?p=35" source="CONFIRM" adv="1">http://bibciter.sourceforge.net/?p=35</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bibciter" name="bibciter">
        <vers num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0325" published="2009-01-29" name="CVE-2009-0325" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in entries/index.php in Ninja Blog 4.8, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the cat parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://www.push55.co.uk/poclibrary/ninjadesignscouk-1.txt" source="MISC">https://www.push55.co.uk/poclibrary/ninjadesignscouk-1.txt</ref>
      <ref url="http://www.securityfocus.com/bid/33351" source="BID">33351</ref>
      <ref url="http://www.push55.co.uk/index.php?s=ad&amp;id=6" source="MISC">http://www.push55.co.uk/index.php?s=ad&amp;id=6</ref>
      <ref url="http://www.milw0rm.com/exploits/7831" source="MILW0RM">7831</ref>
      <ref url="http://secunia.com/advisories/33573" source="SECUNIA" adv="1">33573</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ninjadesigns" name="ninja_blog">
        <vers num="4.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0326" published="2009-01-29" name="CVE-2009-0326" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.php in Dark Age CMS 0.2c beta allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48095" source="XF">darkagecms-login-sql-injection(48095)</ref>
      <ref url="http://www.securityfocus.com/bid/33271" source="BID">33271</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dark_age_cms" name="dark_age_cms">
        <vers num="0.2c" edition="beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0327" published="2009-01-29" name="CVE-2009-0327" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in readbible.php in Free Bible Search PHP Script 1.0 allows remote attackers to execute arbitrary SQL commands via the version parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.seraphimtech.net/repository/Changes.txt" source="CONFIRM">http://www.seraphimtech.net/repository/Changes.txt</ref>
      <ref url="http://www.securityfocus.com/bid/33301" source="BID">33301</ref>
      <ref url="http://www.milw0rm.com/exploits/7798" source="MILW0RM">7798</ref>
      <ref url="http://secunia.com/advisories/33595" source="SECUNIA" adv="1">33595</ref>
      <ref url="http://freshmeat.net/projects/freebiblesearch/?branch_id=77256&amp;release_id=292446" source="MISC">http://freshmeat.net/projects/freebiblesearch/?branch_id=77256&amp;release_id=292446</ref>
    </refs>
    <vuln_soft>
      <prod vendor="seraphimtech" name="free_bible_search_php_script">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0328" published="2009-01-29" name="CVE-2009-0328" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ROBS-PROJECTS Digital Sales IPN (aka DS-IPN.NET or DS-IPN Paypal Shop) stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request for Database/Sales.mdb.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48082" source="XF">digitalsales-sales-information-disclosure(48082)</ref>
      <ref url="http://www.milw0rm.com/exploits/7816" source="MILW0RM">7816</ref>
      <ref url="http://secunia.com/advisories/33602" source="SECUNIA" adv="1">33602</ref>
    </refs>
    <vuln_soft>
      <prod vendor="robs-projects" name="digital_sales_ipn">
        <vers num="_nil_"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0329" published="2009-01-29" name="CVE-2009-0329" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the PcCookBook (com_pccookbook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the recipe_id parameter in a viewrecipe action to index.php, a different vector than CVE-2008-0844.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48088" source="XF">pccookbook-recipeid-sql-injection(48088)</ref>
      <ref url="http://www.securityfocus.com/bid/33346" source="BID">33346</ref>
      <ref url="http://www.milw0rm.com/exploits/7824" source="MILW0RM">7824</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="com_pccookbook">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0330" published="2009-01-29" name="CVE-2009-0330" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in Simple Content Management System (SCMS) 1 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the p parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48081" source="XF">scms-index-file-include(48081)</ref>
      <ref url="http://www.securityfocus.com/bid/33330" source="BID">33330</ref>
      <ref url="http://www.milw0rm.com/exploits/7818" source="MILW0RM">7818</ref>
      <ref url="http://secunia.com/advisories/33608" source="SECUNIA" adv="1">33608</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wss-pro" name="scms">
        <vers num="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0331" published="2009-01-29" name="CVE-2009-0331" modified="2009-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in gallery/comment.php in Enhanced Simple PHP Gallery (ESPG) 1.72 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.  NOTE: the vulnerability may be in my little homepage Comment script. If so, then this should not be treated as a vulnerability in ESPG.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48087" source="XF">espg-comment-directory-traversal(48087)</ref>
      <ref url="http://www.securityfocus.com/bid/33335" source="BID">33335</ref>
      <ref url="http://www.milw0rm.com/exploits/7819" source="MILW0RM">7819</ref>
    </refs>
    <vuln_soft>
      <prod vendor="quirm" name="espg">
        <vers num="1.72"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0332" published="2009-01-29" name="CVE-2009-0332" modified="2009-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in AV Book Library before 1.1 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) admin/edit.php, (2) admin/add.php, (3) lib/book_search.php, and possibly other components.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48084" source="XF">avbook-edit-sql-injection(48084)</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=2219743&amp;group_id=209711&amp;atid=1010816" source="CONFIRM">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=2219743&amp;group_id=209711&amp;atid=1010816</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=654214" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=654214</ref>
      <ref url="http://secunia.com/advisories/33583" source="SECUNIA" adv="1">33583</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avbooklibrary" name="avbooklibrary">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers prev="1" num="1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0333" published="2009-01-29" name="CVE-2009-0333" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the WebAmoeba (WA) Ticket System (com_waticketsystem) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a category action to index.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33353" source="BID">33353</ref>
      <ref url="http://secunia.com/advisories/33577" source="SECUNIA" adv="1">33577</ref>
      <ref url="http://milw0rm.com/exploits/7833" source="MILW0RM">7833</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="com_waticketsystem">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0334" published="2009-01-29" name="CVE-2009-0334" modified="2009-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL commands via the day parameter in an archive action.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48074" source="XF">blogit-index-sql-injection(48074)</ref>
      <ref url="http://www.securityfocus.com/bid/33325" source="BID">33325</ref>
      <ref url="http://www.milw0rm.com/exploits/7806" source="MILW0RM">7806</ref>
      <ref url="http://secunia.com/advisories/33572" source="SECUNIA" adv="1">33572</ref>
    </refs>
    <vuln_soft>
      <prod vendor="katywhitton" name="blogit!">
        <vers num="_nil_"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0335" published="2009-01-29" name="CVE-2009-0335" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to inject arbitrary web script or HTML via the view parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48073" source="XF">blogit-index-xss(48073)</ref>
      <ref url="http://www.securityfocus.com/bid/33325" source="BID">33325</ref>
      <ref url="http://www.milw0rm.com/exploits/7806" source="MILW0RM">7806</ref>
      <ref url="http://secunia.com/advisories/33572" source="SECUNIA" adv="1">33572</ref>
    </refs>
    <vuln_soft>
      <prod vendor="katywhitton" name="blogit!">
        <vers num="_nil_"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0336" published="2009-01-29" name="CVE-2009-0336" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Katy Whitton BlogIt! stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request for database/Blog.mdb.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48075" source="XF">blogit-blog-information-disclosure(48075)</ref>
      <ref url="http://www.milw0rm.com/exploits/7806" source="MILW0RM">7806</ref>
    </refs>
    <vuln_soft>
      <prod vendor="katywhitton" name="blogit!">
        <vers num="_nil_"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0337" published="2009-01-29" name="CVE-2009-0337" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/7806" source="MILW0RM">7806</ref>
      <ref url="http://secunia.com/advisories/33572" source="SECUNIA" adv="1">33572</ref>
    </refs>
    <vuln_soft>
      <prod vendor="katywhitton" name="blogit!">
        <vers num="_nil_"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0338" published="2009-01-29" name="CVE-2009-0338" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in inc_webblogmanager.asp in DMXReady Blog Manager allows remote attackers to inject arbitrary web script or HTML via the CategoryID parameter in a refer action.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48053" source="XF">blogmanager-incwebblogmanager-xss(48053)</ref>
      <ref url="http://www.securityfocus.com/bid/33314" source="BID">33314</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500146/100/0/threaded" source="BUGTRAQ">20090116 DMXReady Blog Manager (SQL/XSS)</ref>
      <ref url="http://secunia.com/advisories/33601" source="SECUNIA" adv="1">33601</ref>
      <ref url="http://dmxready.helpserve.com/index.php?_m=news&amp;_a=viewnews&amp;newsid=12" source="MISC" adv="1">http://dmxready.helpserve.com/index.php?_m=news&amp;_a=viewnews&amp;newsid=12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dmxready" name="blog_manager">
        <vers num="_nil"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0339" published="2009-01-29" name="CVE-2009-0339" modified="2009-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in inc_webblogmanager.asp in DMXReady Blog Manager allows remote attackers to execute arbitrary SQL commands via the itemID parameter in a view action.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48054" source="XF">blogmanager-incwebblogmanager-sql-injection(48054)</ref>
      <ref url="http://www.securityfocus.com/bid/33314" source="BID">33314</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500146/100/0/threaded" source="BUGTRAQ">20090116 DMXReady Blog Manager (SQL/XSS)</ref>
      <ref url="http://secunia.com/advisories/33601" source="SECUNIA" adv="1">33601</ref>
      <ref url="http://dmxready.helpserve.com/index.php?_m=news&amp;_a=viewnews&amp;newsid=12" source="MISC" adv="1">http://dmxready.helpserve.com/index.php?_m=news&amp;_a=viewnews&amp;newsid=12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dmxready" name="blog_manager">
        <vers num="_nil_"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0340" published="2009-01-29" name="CVE-2009-0340" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in Simple PHP Newsletter 1.5 allow remote attackers to read arbitrary files via a .. (dot dot) in the olang parameter to (1) mail.php and (2) mailbar.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48089" source="XF">simplephpnewsletter-mail-file-include(48089)</ref>
      <ref url="http://www.securityfocus.com/bid/33327" source="BID">33327</ref>
      <ref url="http://www.milw0rm.com/exploits/7813" source="MILW0RM">7813</ref>
    </refs>
    <vuln_soft>
      <prod vendor="quirm" name="simple_php_newsletter">
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0341" published="2009-01-29" name="CVE-2009-0341" modified="2009-02-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The shell32 module in Microsoft Internet Explorer 7.0 on Windows XP SP3 might allow remote attackers to execute arbitrary code via a long VALUE attribute in an INPUT element, possibly related to a stack consumption vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33494" source="BID">33494</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500472/100/0/threaded" source="BUGTRAQ">20090128 Internet explorer 7.0 stack overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0342" published="2009-01-29" name="CVE-2009-0342" modified="2012-03-19" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Niels Provos Systrace before 1.6f on the x86_64 Linux platform allows local users to bypass intended access restrictions by making a 64-bit syscall with a syscall number that corresponds to a policy-compliant 32-bit syscall.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33417" source="BID">33417</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500377/100/0/threaded" source="BUGTRAQ">20090123 Problems with syscall filtering technologies on Linux</ref>
      <ref url="http://www.citi.umich.edu/u/provos/systrace/" source="CONFIRM">http://www.citi.umich.edu/u/provos/systrace/</ref>
      <ref url="http://scarybeastsecurity.blogspot.com/2009/01/bypassing-syscall-filtering.html" source="MISC">http://scarybeastsecurity.blogspot.com/2009/01/bypassing-syscall-filtering.html</ref>
      <ref url="http://scary.beasts.org/security/CESA-2009-001.html" source="MISC">http://scary.beasts.org/security/CESA-2009-001.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="provos" name="systrace">
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.4"/>
        <vers num="1.5"/>
        <vers num="1.6"/>
        <vers num="1.6a"/>
        <vers num="1.6b"/>
        <vers num="1.6c"/>
        <vers num="1.6d"/>
        <vers prev="1" num="1.6e"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0343" published="2009-01-29" name="CVE-2009-0343" modified="2012-03-19" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Niels Provos Systrace 1.6f and earlier on the x86_64 Linux platform allows local users to bypass intended access restrictions by making a 32-bit syscall with a syscall number that corresponds to a policy-compliant 64-bit syscall, related to race conditions that occur in monitoring 64-bit processes.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33417" source="BID">33417</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500377/100/0/threaded" source="BUGTRAQ">20090123 Problems with syscall filtering technologies on Linux</ref>
      <ref url="http://www.citi.umich.edu/u/provos/systrace/" source="MISC">http://www.citi.umich.edu/u/provos/systrace/</ref>
      <ref url="http://scarybeastsecurity.blogspot.com/2009/01/bypassing-syscall-filtering.html" source="MISC">http://scarybeastsecurity.blogspot.com/2009/01/bypassing-syscall-filtering.html</ref>
      <ref url="http://scary.beasts.org/security/CESA-2009-001.html" source="MISC">http://scary.beasts.org/security/CESA-2009-001.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="niels_provos" name="systrace">
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.4"/>
        <vers num="1.5"/>
        <vers num="1.6"/>
        <vers num="1.6a"/>
        <vers num="1.6b"/>
        <vers num="1.6c"/>
        <vers num="1.6d"/>
        <vers prev="1" num="1.6e"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0344" published="2009-01-29" name="CVE-2009-0344" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Embedded Lights Out Manager (ELOM) on the Sun Fire X2100 M2 and X2200 M2 x86 platforms before SP/BMC firmware 3.20 allows remote attackers to obtain privileged ELOM login access or execute arbitrary Service Processor (SP) commands via unknown vectors, aka Bug ID 6633175, a different vulnerability than CVE-2007-5717.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-239886-1" source="SUNALERT" patch="1" adv="1">239886</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48329" source="XF">sunfire-elom-unauth-access(48329)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0281" source="VUPEN">ADV-2009-0281</ref>
      <ref url="http://www.securitytracker.com/id?1021646" source="SECTRACK">1021646</ref>
      <ref url="http://www.securityfocus.com/bid/33506" source="BID">33506</ref>
      <ref url="http://secunia.com/advisories/33726" source="SECUNIA">33726</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="fire_x2100_m2">
        <vers prev="1" num="3.19" edition="_nil_"/>
        <vers prev="1" num="3.19" edition="_nil_:x86"/>
      </prod>
      <prod vendor="sun" name="fire_x2200_m2">
        <vers prev="1" num="2.19" edition="_nil_"/>
        <vers prev="1" num="2.19" edition="_nil_:x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0345" published="2009-01-29" name="CVE-2009-0345" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Embedded Lights Out Manager (ELOM) on the Sun Fire X2100 M2 and X2200 M2 x86 platforms before SP/BMC firmware 3.20 allows remote attackers to obtain privileged ELOM login access or execute arbitrary Service Processor (SP) commands via unknown vectors, aka Bug ID 6648082, a different vulnerability than CVE-2007-5717.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-239886-1" source="SUNALERT" patch="1" adv="1">239886</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48329" source="XF">sunfire-elom-unauth-access(48329)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0281" source="VUPEN">ADV-2009-0281</ref>
      <ref url="http://www.securitytracker.com/id?1021646" source="SECTRACK">1021646</ref>
      <ref url="http://www.securityfocus.com/bid/33506" source="BID">33506</ref>
      <ref url="http://secunia.com/advisories/33726" source="SECUNIA">33726</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="fire_x2100_m2">
        <vers prev="1" num="3.19" edition="_nil_"/>
        <vers prev="1" num="3.19" edition="_nil_:x86"/>
      </prod>
      <prod vendor="sun" name="fire_x2200_m2">
        <vers prev="1" num="2.19" edition="_nil_"/>
        <vers prev="1" num="2.19" edition="_nil_:x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0346" published="2009-01-29" name="CVE-2009-0346" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The IP-in-IP packet processing implementation in the IPsec and IP stacks in the kernel in Sun Solaris 9 and 10, and OpenSolaris snv_01 though snv_85, allows local users to cause a denial of service (panic) via a self-encapsulated packet that lacks IPsec protection.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-240086-1" source="SUNALERT" patch="1" adv="1">240086</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-114344-38-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-114344-38-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48328" source="XF">solaris-ipinip-dos(48328)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0365" source="VUPEN">ADV-2009-0365</ref>
      <ref url="http://www.securityfocus.com/bid/33504" source="BID">33504</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-043.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-043.htm</ref>
      <ref url="http://secunia.com/advisories/33727" source="SECUNIA">33727</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6088" source="OVAL">oval:org.mitre.oval:def:6088</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_01" edition=""/>
        <vers num="snv_01" edition=":sparc"/>
        <vers num="snv_01" edition=":x86"/>
        <vers num="snv_02" edition=""/>
        <vers num="snv_02" edition=":sparc"/>
        <vers num="snv_02" edition=":x86"/>
        <vers num="snv_03" edition=""/>
        <vers num="snv_03" edition=":x86"/>
        <vers num="snv_03" edition=":sparc"/>
        <vers num="snv_04" edition=""/>
        <vers num="snv_04" edition=":x86"/>
        <vers num="snv_04" edition=":sparc"/>
        <vers num="snv_05" edition=""/>
        <vers num="snv_05" edition=":sparc"/>
        <vers num="snv_05" edition=":x86"/>
        <vers num="snv_06" edition=""/>
        <vers num="snv_06" edition=":sparc"/>
        <vers num="snv_06" edition=":x86"/>
        <vers num="snv_07" edition=""/>
        <vers num="snv_07" edition=":sparc"/>
        <vers num="snv_07" edition=":x86"/>
        <vers num="snv_08" edition=""/>
        <vers num="snv_08" edition=":x86"/>
        <vers num="snv_08" edition=":sparc"/>
        <vers num="snv_09" edition=""/>
        <vers num="snv_09" edition=":sparc"/>
        <vers num="snv_09" edition=":x86"/>
        <vers num="snv_10" edition=""/>
        <vers num="snv_10" edition=":x86"/>
        <vers num="snv_10" edition=":sparc"/>
        <vers num="snv_100" edition=""/>
        <vers num="snv_100" edition=":x86"/>
        <vers num="snv_100" edition=":sparc"/>
        <vers num="snv_101" edition=""/>
        <vers num="snv_101" edition=":x86"/>
        <vers num="snv_101" edition=":sparc"/>
        <vers num="snv_102" edition=""/>
        <vers num="snv_102" edition=":x86"/>
        <vers num="snv_102" edition=":sparc"/>
        <vers num="snv_103" edition=""/>
        <vers num="snv_103" edition=":sparc"/>
        <vers num="snv_103" edition=":x86"/>
        <vers num="snv_104" edition=""/>
        <vers num="snv_104" edition=":x86"/>
        <vers num="snv_104" edition=":sparc"/>
        <vers num="snv_105" edition=""/>
        <vers num="snv_105" edition=":x86"/>
        <vers num="snv_105" edition=":sparc"/>
        <vers num="snv_106" edition=""/>
        <vers num="snv_106" edition=":sparc"/>
        <vers num="snv_106" edition=":x86"/>
        <vers num="snv_107" edition=""/>
        <vers num="snv_107" edition=":sparc"/>
        <vers num="snv_107" edition=":x86"/>
        <vers num="snv_11" edition=""/>
        <vers num="snv_11" edition=":x86"/>
        <vers num="snv_11" edition=":sparc"/>
        <vers num="snv_12" edition=""/>
        <vers num="snv_12" edition=":x86"/>
        <vers num="snv_12" edition=":sparc"/>
        <vers num="snv_13" edition=""/>
        <vers num="snv_13" edition=":x86"/>
        <vers num="snv_13" edition=":sparc"/>
        <vers num="snv_14" edition=""/>
        <vers num="snv_14" edition=":x86"/>
        <vers num="snv_14" edition=":sparc"/>
        <vers num="snv_15" edition=""/>
        <vers num="snv_15" edition=":x86"/>
        <vers num="snv_15" edition=":sparc"/>
        <vers num="snv_16" edition=""/>
        <vers num="snv_16" edition=":sparc"/>
        <vers num="snv_16" edition=":x86"/>
        <vers num="snv_17" edition=""/>
        <vers num="snv_17" edition=":x86"/>
        <vers num="snv_17" edition=":sparc"/>
        <vers num="snv_18" edition=""/>
        <vers num="snv_18" edition=":x86"/>
        <vers num="snv_18" edition=":sparc"/>
        <vers num="snv_19" edition=""/>
        <vers num="snv_19" edition=":sparc"/>
        <vers num="snv_19" edition=":x86"/>
        <vers num="snv_20" edition=""/>
        <vers num="snv_20" edition=":x86"/>
        <vers num="snv_20" edition=":sparc"/>
        <vers num="snv_21" edition=""/>
        <vers num="snv_21" edition=":x86"/>
        <vers num="snv_21" edition=":sparc"/>
        <vers num="snv_22" edition=""/>
        <vers num="snv_22" edition=":sparc"/>
        <vers num="snv_22" edition=":x86"/>
        <vers num="snv_23" edition=""/>
        <vers num="snv_23" edition=":sparc"/>
        <vers num="snv_23" edition=":x86"/>
        <vers num="snv_24" edition=""/>
        <vers num="snv_24" edition=":sparc"/>
        <vers num="snv_24" edition=":x86"/>
        <vers num="snv_25" edition=""/>
        <vers num="snv_25" edition=":sparc"/>
        <vers num="snv_25" edition=":x86"/>
        <vers num="snv_26" edition=""/>
        <vers num="snv_26" edition=":sparc"/>
        <vers num="snv_26" edition=":x86"/>
        <vers num="snv_27" edition=""/>
        <vers num="snv_27" edition=":sparc"/>
        <vers num="snv_27" edition=":x86"/>
        <vers num="snv_28" edition=""/>
        <vers num="snv_28" edition=":sparc"/>
        <vers num="snv_28" edition=":x86"/>
        <vers num="snv_29" edition=""/>
        <vers num="snv_29" edition=":x86"/>
        <vers num="snv_29" edition=":sparc"/>
        <vers num="snv_30" edition=""/>
        <vers num="snv_30" edition=":sparc"/>
        <vers num="snv_30" edition=":x86"/>
        <vers num="snv_31" edition=""/>
        <vers num="snv_31" edition=":sparc"/>
        <vers num="snv_31" edition=":x86"/>
        <vers num="snv_32" edition=""/>
        <vers num="snv_32" edition=":x86"/>
        <vers num="snv_32" edition=":sparc"/>
        <vers num="snv_33" edition=""/>
        <vers num="snv_33" edition=":x86"/>
        <vers num="snv_33" edition=":sparc"/>
        <vers num="snv_34" edition=""/>
        <vers num="snv_34" edition=":sparc"/>
        <vers num="snv_34" edition=":x86"/>
        <vers num="snv_35" edition=""/>
        <vers num="snv_35" edition=":sparc"/>
        <vers num="snv_35" edition=":x86"/>
        <vers num="snv_36" edition=""/>
        <vers num="snv_36" edition=":sparc"/>
        <vers num="snv_36" edition=":x86"/>
        <vers num="snv_37" edition=""/>
        <vers num="snv_37" edition=":sparc"/>
        <vers num="snv_37" edition=":x86"/>
        <vers num="snv_38" edition=""/>
        <vers num="snv_38" edition=":sparc"/>
        <vers num="snv_38" edition=":x86"/>
        <vers num="snv_39" edition=""/>
        <vers num="snv_39" edition=":sparc"/>
        <vers num="snv_39" edition=":x86"/>
        <vers num="snv_40" edition=""/>
        <vers num="snv_40" edition=":x86"/>
        <vers num="snv_40" edition=":sparc"/>
        <vers num="snv_41" edition=""/>
        <vers num="snv_41" edition=":sparc"/>
        <vers num="snv_41" edition=":x86"/>
        <vers num="snv_42" edition=""/>
        <vers num="snv_42" edition=":x86"/>
        <vers num="snv_42" edition=":sparc"/>
        <vers num="snv_43" edition=""/>
        <vers num="snv_43" edition=":sparc"/>
        <vers num="snv_43" edition=":x86"/>
        <vers num="snv_44" edition=""/>
        <vers num="snv_44" edition=":x86"/>
        <vers num="snv_44" edition=":sparc"/>
        <vers num="snv_45" edition=""/>
        <vers num="snv_45" edition=":x86"/>
        <vers num="snv_45" edition=":sparc"/>
        <vers num="snv_46" edition=""/>
        <vers num="snv_46" edition=":sparc"/>
        <vers num="snv_46" edition=":x86"/>
        <vers num="snv_47" edition=""/>
        <vers num="snv_47" edition=":x86"/>
        <vers num="snv_47" edition=":sparc"/>
        <vers num="snv_48" edition=""/>
        <vers num="snv_48" edition=":sparc"/>
        <vers num="snv_48" edition=":x86"/>
        <vers num="snv_49" edition=""/>
        <vers num="snv_49" edition=":sparc"/>
        <vers num="snv_49" edition=":x86"/>
        <vers num="snv_50" edition=""/>
        <vers num="snv_50" edition=":sparc"/>
        <vers num="snv_50" edition=":x86"/>
        <vers num="snv_51" edition=""/>
        <vers num="snv_51" edition=":x86"/>
        <vers num="snv_51" edition=":sparc"/>
        <vers num="snv_52" edition=""/>
        <vers num="snv_52" edition=":x86"/>
        <vers num="snv_52" edition=":sparc"/>
        <vers num="snv_53" edition=""/>
        <vers num="snv_53" edition=":sparc"/>
        <vers num="snv_53" edition=":x86"/>
        <vers num="snv_54" edition=""/>
        <vers num="snv_54" edition=":sparc"/>
        <vers num="snv_54" edition=":x86"/>
        <vers num="snv_55" edition=""/>
        <vers num="snv_55" edition=":sparc"/>
        <vers num="snv_55" edition=":x86"/>
        <vers num="snv_56" edition=""/>
        <vers num="snv_56" edition=":x86"/>
        <vers num="snv_56" edition=":sparc"/>
        <vers num="snv_57" edition=""/>
        <vers num="snv_57" edition=":x86"/>
        <vers num="snv_57" edition=":sparc"/>
        <vers num="snv_58" edition=""/>
        <vers num="snv_58" edition=":sparc"/>
        <vers num="snv_58" edition=":x86"/>
        <vers num="snv_59" edition=""/>
        <vers num="snv_59" edition=":sparc"/>
        <vers num="snv_59" edition=":x86"/>
        <vers num="snv_60" edition=""/>
        <vers num="snv_60" edition=":x86"/>
        <vers num="snv_60" edition=":sparc"/>
        <vers num="snv_61" edition=""/>
        <vers num="snv_61" edition=":sparc"/>
        <vers num="snv_61" edition=":x86"/>
        <vers num="snv_62" edition=""/>
        <vers num="snv_62" edition=":x86"/>
        <vers num="snv_62" edition=":sparc"/>
        <vers num="snv_63" edition=""/>
        <vers num="snv_63" edition=":x86"/>
        <vers num="snv_63" edition=":sparc"/>
        <vers num="snv_64" edition=""/>
        <vers num="snv_64" edition=":x86"/>
        <vers num="snv_64" edition=":sparc"/>
        <vers num="snv_65" edition=""/>
        <vers num="snv_65" edition=":sparc"/>
        <vers num="snv_65" edition=":x86"/>
        <vers num="snv_66" edition=""/>
        <vers num="snv_66" edition=":x86"/>
        <vers num="snv_66" edition=":sparc"/>
        <vers num="snv_67" edition=""/>
        <vers num="snv_67" edition=":sparc"/>
        <vers num="snv_67" edition=":x86"/>
        <vers num="snv_68" edition=""/>
        <vers num="snv_68" edition=":x86"/>
        <vers num="snv_68" edition=":sparc"/>
        <vers num="snv_69" edition=""/>
        <vers num="snv_69" edition=":sparc"/>
        <vers num="snv_69" edition=":x86"/>
        <vers num="snv_70" edition=""/>
        <vers num="snv_70" edition=":sparc"/>
        <vers num="snv_70" edition=":x86"/>
        <vers num="snv_71" edition=""/>
        <vers num="snv_71" edition=":sparc"/>
        <vers num="snv_71" edition=":x86"/>
        <vers num="snv_72" edition=""/>
        <vers num="snv_72" edition=":x86"/>
        <vers num="snv_72" edition=":sparc"/>
        <vers num="snv_73" edition=""/>
        <vers num="snv_73" edition=":x86"/>
        <vers num="snv_73" edition=":sparc"/>
        <vers num="snv_74" edition=""/>
        <vers num="snv_74" edition=":x86"/>
        <vers num="snv_74" edition=":sparc"/>
        <vers num="snv_75" edition=""/>
        <vers num="snv_75" edition=":x86"/>
        <vers num="snv_75" edition=":sparc"/>
        <vers num="snv_76" edition=""/>
        <vers num="snv_76" edition=":sparc"/>
        <vers num="snv_76" edition=":x86"/>
        <vers num="snv_77" edition=""/>
        <vers num="snv_77" edition=":sparc"/>
        <vers num="snv_77" edition=":x86"/>
        <vers num="snv_78" edition=""/>
        <vers num="snv_78" edition=":sparc"/>
        <vers num="snv_78" edition=":x86"/>
        <vers num="snv_79" edition=""/>
        <vers num="snv_79" edition=":x86"/>
        <vers num="snv_79" edition=":sparc"/>
        <vers num="snv_80" edition=""/>
        <vers num="snv_80" edition=":x86"/>
        <vers num="snv_80" edition=":sparc"/>
        <vers num="snv_81" edition=""/>
        <vers num="snv_81" edition=":x86"/>
        <vers num="snv_81" edition=":sparc"/>
        <vers num="snv_82" edition=""/>
        <vers num="snv_82" edition=":x86"/>
        <vers num="snv_82" edition=":sparc"/>
        <vers num="snv_83" edition=""/>
        <vers num="snv_83" edition=":sparc"/>
        <vers num="snv_83" edition=":x86"/>
        <vers num="snv_84" edition=""/>
        <vers num="snv_84" edition=":x86"/>
        <vers num="snv_84" edition=":sparc"/>
        <vers num="snv_85" edition=""/>
        <vers num="snv_85" edition=":sparc"/>
        <vers num="snv_85" edition=":x86"/>
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10" edition=""/>
        <vers num="10" edition=":sparc"/>
        <vers num="10" edition=":x86"/>
        <vers num="9" edition=""/>
        <vers num="9" edition=":sparc"/>
        <vers num="9" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0347" published="2009-01-29" name="CVE-2009-0347" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Open redirect vulnerability in cs.html in the Autonomy (formerly Verity) Ultraseek search engine allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/202753" source="CERT-VN">VU#202753</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48336" source="XF">ultraseek-cs-phishing(48336)</ref>
      <ref url="http://www.ultraseek.com/forums/thread.jspa?messageID=9818" source="MISC">http://www.ultraseek.com/forums/thread.jspa?messageID=9818</ref>
      <ref url="http://www.securityfocus.com/bid/33500" source="BID">33500</ref>
      <ref url="http://sunbeltblog.blogspot.com/2009/01/constant-stream-of-ultraseek-redirects.html" source="MISC">http://sunbeltblog.blogspot.com/2009/01/constant-stream-of-ultraseek-redirects.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="autonomy" name="ultraseek">
        <vers num="_nil_"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0348" published="2009-01-29" name="CVE-2009-0348" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The login module in Sun Java System Access Manager 6 2005Q1 (aka 6.3), 7 2005Q4 (aka 7.0), and 7.1 responds differently to a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-242026-1" source="SUNALERT" patch="1" adv="1">242026</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-119465-15-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-119465-15-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48283" source="XF">sun-jsam-username-info-disclosure(48283)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0269" source="VUPEN">ADV-2009-0269</ref>
      <ref url="http://www.securityfocus.com/bid/33489" source="BID">33489</ref>
      <ref url="http://secunia.com/advisories/33688" source="SECUNIA" adv="1">33688</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_access_manager">
        <vers num="6.3_2005q1" edition=""/>
        <vers num="6.3_2005q1" edition=":solaris_10_sparc"/>
        <vers num="6.3_2005q1" edition=":solaris_8_windows"/>
        <vers num="6.3_2005q1" edition=":solaris_8_linux"/>
        <vers num="6.3_2005q1" edition=":solaris_9_linux"/>
        <vers num="6.3_2005q1" edition=":solaris_9_sparc"/>
        <vers num="6.3_2005q1" edition=":solaris_10_linux"/>
        <vers num="6.3_2005q1" edition=":solaris_8_x86"/>
        <vers num="6.3_2005q1" edition=":solaris_10_x86"/>
        <vers num="6.3_2005q1" edition=":solaris_10_windows"/>
        <vers num="6.3_2005q1" edition=":solaris_9_x86"/>
        <vers num="6.3_2005q1" edition=":solaris_8_sparc"/>
        <vers num="6.3_2005q1" edition=":solaris_9_windows"/>
        <vers num="7.1" edition=""/>
        <vers num="7.1" edition=":solaris_9_sparc"/>
        <vers num="7.1" edition=":solaris_10_linux"/>
        <vers num="7.1" edition=":solaris_8_x86"/>
        <vers num="7.1" edition=":solaris_10_x86"/>
        <vers num="7.1" edition=":solaris_10_sparc"/>
        <vers num="7.1" edition=":solaris_9_linux"/>
        <vers num="7.1" edition=":solaris_8_windows"/>
        <vers num="7.1" edition=":solaris_10_windows"/>
        <vers num="7.1" edition=":solaris_8_sparc"/>
        <vers num="7.1" edition=":solaris_9_windows"/>
        <vers num="7.1" edition=":solaris_8_linux"/>
        <vers num="7.1" edition=":solaris_9_x86"/>
        <vers num="7_2005q4" edition=""/>
        <vers num="7_2005q4" edition=":solaris_9_x86"/>
        <vers num="7_2005q4" edition=":solaris_8_x86"/>
        <vers num="7_2005q4" edition=":solaris_10_linux"/>
        <vers num="7_2005q4" edition=":solaris_10_windows"/>
        <vers num="7_2005q4" edition=":solaris_10_sparc"/>
        <vers num="7_2005q4" edition=":solaris_9_windows"/>
        <vers num="7_2005q4" edition=":solaris_10_x86"/>
        <vers num="7_2005q4" edition=":solaris_8_sparc"/>
        <vers num="7_2005q4" edition=":solaris_9_sparc"/>
        <vers num="7_2005q4" edition=":solaris_8_windows"/>
        <vers num="7_2005q4" edition=":solaris_9_linux"/>
        <vers num="7_2005q4" edition=":solaris_8_linux"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0349" published="2009-01-29" name="CVE-2009-0349" modified="2009-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in FTPShell Server 4.3 allows user-assisted remote attackers to cause a denial of service (persistent daemon crash) and possibly execute arbitrary code via a long string in a licensing key (aka .key) file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/7852" source="MILW0RM">7852</ref>
      <ref url="http://secunia.com/advisories/33597" source="SECUNIA" adv="1">33597</ref>
      <ref url="http://osvdb.org/51510" source="OSVDB">51510</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ftpshell" name="ftpshell_server">
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0350" published="2009-01-29" name="CVE-2009-0350" modified="2009-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Merak Media Player 3.2 allows remote attackers to execute arbitrary code via a long string in a .m3u playlist file, related to the status bar icon's tooltip.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/7857" source="MILW0RM">7857</ref>
      <ref url="http://secunia.com/advisories/33645" source="SECUNIA" adv="1">33645</ref>
      <ref url="http://osvdb.org/51565" source="OSVDB">51565</ref>
    </refs>
    <vuln_soft>
      <prod vendor="merak" name="media_player">
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0351" published="2009-01-29" name="CVE-2009-0351" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in WFTPSRV.exe in WinFTP 2.3.0 allows remote authenticated users to execute arbitrary code via a long LIST argument beginning with an * (asterisk) character.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48263" source="XF">winftp-list-bo(48263)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0254" source="VUPEN">ADV-2009-0254</ref>
      <ref url="http://www.securityfocus.com/bid/33454" source="BID">33454</ref>
      <ref url="http://www.milw0rm.com/exploits/7875" source="MILW0RM">7875</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wftpserver" name="winftp_ftp_server">
        <vers num="2.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0352" published="2009-02-04" name="CVE-2009-0352" modified="2011-09-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the layout engine and destruction of arbitrary layout objects by the nsViewManager::Composite function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg01077.html" source="FEDORA">FEDORA-2009-3101</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00771.html" source="FEDORA">FEDORA-2009-2884</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00769.html" source="FEDORA">FEDORA-2009-2882</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00240.html" source="FEDORA">FEDORA-2009-1399</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=461027" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=461027</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=449006" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=449006</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=437142" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=437142</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=431705" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=431705</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=422301" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=422301</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=422283" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=422283</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=421839" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=421839</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=420697" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=420697</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=416461" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=416461</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=401042" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=401042</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=331088" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=331088</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0313" source="VUPEN">ADV-2009-0313</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-741-1" source="UBUNTU">USN-741-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-717-1" source="UBUNTU">USN-717-1</ref>
      <ref url="http://www.securitytracker.com/id?1021663" source="SECTRACK">1021663</ref>
      <ref url="http://www.securityfocus.com/bid/33598" source="BID">33598</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0258.html" source="REDHAT">RHSA-2009:0258</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0257.html" source="REDHAT">RHSA-2009:0257</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-01.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-01.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:083" source="MANDRIVA">MDVSA-2009:083</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:044" source="MANDRIVA">MDVSA-2009:044</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1830" source="DEBIAN">DSA-1830</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.433952" source="SLACKWARE">SSA:2009-083-03</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.405420" source="SLACKWARE">SSA:2009-083-02</ref>
      <ref url="http://secunia.com/advisories/34527" source="SECUNIA">34527</ref>
      <ref url="http://secunia.com/advisories/34464" source="SECUNIA">34464</ref>
      <ref url="http://secunia.com/advisories/34462" source="SECUNIA">34462</ref>
      <ref url="http://secunia.com/advisories/34417" source="SECUNIA">34417</ref>
      <ref url="http://secunia.com/advisories/34387" source="SECUNIA">34387</ref>
      <ref url="http://secunia.com/advisories/34324" source="SECUNIA">34324</ref>
      <ref url="http://secunia.com/advisories/33869" source="SECUNIA">33869</ref>
      <ref url="http://secunia.com/advisories/33846" source="SECUNIA">33846</ref>
      <ref url="http://secunia.com/advisories/33841" source="SECUNIA">33841</ref>
      <ref url="http://secunia.com/advisories/33831" source="SECUNIA">33831</ref>
      <ref url="http://secunia.com/advisories/33816" source="SECUNIA">33816</ref>
      <ref url="http://secunia.com/advisories/33809" source="SECUNIA">33809</ref>
      <ref url="http://secunia.com/advisories/33808" source="SECUNIA">33808</ref>
      <ref url="http://secunia.com/advisories/33802" source="SECUNIA">33802</ref>
      <ref url="http://secunia.com/advisories/33799" source="SECUNIA">33799</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0256.html" source="REDHAT">RHSA-2009:0256</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10699" source="OVAL">oval:org.mitre.oval:def:10699</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00009.html" source="SUSE">SUSE-SA:2009:023</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00001.html" source="SUSE">SUSE-SA:2009:009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers prev="1" num="1.1.13"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5" edition="beta"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.13"/>
        <vers num="1.5.0.14"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="2.0.0.0"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers prev="1" num="2.0.0.19"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0353" published="2009-02-04" name="CVE-2009-0353" modified="2011-09-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the JavaScript engine.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg01077.html" source="FEDORA">FEDORA-2009-3101</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00771.html" source="FEDORA">FEDORA-2009-2884</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00769.html" source="FEDORA">FEDORA-2009-2882</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00240.html" source="FEDORA">FEDORA-2009-1399</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=452913" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=452913</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0313" source="VUPEN">ADV-2009-0313</ref>
      <ref url="http://www.ubuntu.com/usn/usn-717-1" source="UBUNTU">USN-717-1</ref>
      <ref url="http://www.securitytracker.com/id?1021663" source="SECTRACK">1021663</ref>
      <ref url="http://www.securityfocus.com/bid/33598" source="BID">33598</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0258.html" source="REDHAT">RHSA-2009:0258</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0257.html" source="REDHAT">RHSA-2009:0257</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-01.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-01.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:083" source="MANDRIVA">MDVSA-2009:083</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:044" source="MANDRIVA">MDVSA-2009:044</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1830" source="DEBIAN">DSA-1830</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.433952" source="SLACKWARE">SSA:2009-083-03</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.405420" source="SLACKWARE">SSA:2009-083-02</ref>
      <ref url="http://secunia.com/advisories/34527" source="SECUNIA">34527</ref>
      <ref url="http://secunia.com/advisories/34464" source="SECUNIA">34464</ref>
      <ref url="http://secunia.com/advisories/34462" source="SECUNIA">34462</ref>
      <ref url="http://secunia.com/advisories/34417" source="SECUNIA">34417</ref>
      <ref url="http://secunia.com/advisories/34324" source="SECUNIA">34324</ref>
      <ref url="http://secunia.com/advisories/33869" source="SECUNIA">33869</ref>
      <ref url="http://secunia.com/advisories/33846" source="SECUNIA">33846</ref>
      <ref url="http://secunia.com/advisories/33841" source="SECUNIA">33841</ref>
      <ref url="http://secunia.com/advisories/33831" source="SECUNIA">33831</ref>
      <ref url="http://secunia.com/advisories/33816" source="SECUNIA">33816</ref>
      <ref url="http://secunia.com/advisories/33809" source="SECUNIA">33809</ref>
      <ref url="http://secunia.com/advisories/33808" source="SECUNIA">33808</ref>
      <ref url="http://secunia.com/advisories/33802" source="SECUNIA">33802</ref>
      <ref url="http://secunia.com/advisories/33799" source="SECUNIA">33799</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0256.html" source="REDHAT">RHSA-2009:0256</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11193" source="OVAL">oval:org.mitre.oval:def:11193</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00009.html" source="SUSE">SUSE-SA:2009:023</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00001.html" source="SUSE">SUSE-SA:2009:009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers prev="1" num="1.1.13"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5" edition="beta"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.13"/>
        <vers num="1.5.0.14"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="2.0.0.0"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers prev="1" num="2.0.0.19"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0354" published="2009-02-04" name="CVE-2009-0354" modified="2011-09-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitrary window and conduct cross-site scripting (XSS) attacks, via vectors involving a chrome XBL method and the window.eval function.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00240.html" source="FEDORA">FEDORA-2009-1399</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=468581" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=468581</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0313" source="VUPEN">ADV-2009-0313</ref>
      <ref url="http://www.ubuntu.com/usn/usn-717-1" source="UBUNTU">USN-717-1</ref>
      <ref url="http://www.securitytracker.com/id?1021664" source="SECTRACK">1021664</ref>
      <ref url="http://www.securityfocus.com/bid/33598" source="BID">33598</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-02.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-02.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:044" source="MANDRIVA">MDVSA-2009:044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm</ref>
      <ref url="http://secunia.com/advisories/33869" source="SECUNIA">33869</ref>
      <ref url="http://secunia.com/advisories/33846" source="SECUNIA">33846</ref>
      <ref url="http://secunia.com/advisories/33841" source="SECUNIA">33841</ref>
      <ref url="http://secunia.com/advisories/33831" source="SECUNIA">33831</ref>
      <ref url="http://secunia.com/advisories/33809" source="SECUNIA">33809</ref>
      <ref url="http://secunia.com/advisories/33799" source="SECUNIA">33799</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0256.html" source="REDHAT">RHSA-2009:0256</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9796" source="OVAL">oval:org.mitre.oval:def:9796</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00001.html" source="SUSE">SUSE-SA:2009:009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0" edition="alpha"/>
        <vers num="3.0" edition="beta2"/>
        <vers num="3.0" edition="beta5"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0355" published="2009-02-04" name="CVE-2009-0355" modified="2011-09-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:N/A:N)" CVSS_score="5.4" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="4.9" CVSS_base_score="5.4">
    <desc>
      <descript source="cve">components/sessionstore/src/nsSessionStore.js in Mozilla Firefox before 3.0.6 does not block changes of INPUT elements to type="file" during tab restoration, which allows user-assisted remote attackers to read arbitrary files on a client machine via a crafted INPUT element.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33598" source="BID" patch="1">33598</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00771.html" source="FEDORA">FEDORA-2009-2884</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00769.html" source="FEDORA">FEDORA-2009-2882</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00240.html" source="FEDORA">FEDORA-2009-1399</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=466937" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=466937</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0313" source="VUPEN">ADV-2009-0313</ref>
      <ref url="http://www.ubuntu.com/usn/usn-717-2" source="UBUNTU">USN-717-2</ref>
      <ref url="http://www.ubuntu.com/usn/usn-717-1" source="UBUNTU">USN-717-1</ref>
      <ref url="http://www.securitytracker.com/id?1021665" source="SECTRACK">1021665</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0258.html" source="REDHAT">RHSA-2009:0258</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0257.html" source="REDHAT">RHSA-2009:0257</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-03.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-03.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:044" source="MANDRIVA">MDVSA-2009:044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm</ref>
      <ref url="http://secunia.com/advisories/34417" source="SECUNIA" adv="1">34417</ref>
      <ref url="http://secunia.com/advisories/34324" source="SECUNIA" adv="1">34324</ref>
      <ref url="http://secunia.com/advisories/33869" source="SECUNIA" adv="1">33869</ref>
      <ref url="http://secunia.com/advisories/33846" source="SECUNIA" adv="1">33846</ref>
      <ref url="http://secunia.com/advisories/33841" source="SECUNIA" adv="1">33841</ref>
      <ref url="http://secunia.com/advisories/33831" source="SECUNIA" adv="1">33831</ref>
      <ref url="http://secunia.com/advisories/33816" source="SECUNIA" adv="1">33816</ref>
      <ref url="http://secunia.com/advisories/33809" source="SECUNIA" adv="1">33809</ref>
      <ref url="http://secunia.com/advisories/33808" source="SECUNIA" adv="1">33808</ref>
      <ref url="http://secunia.com/advisories/33799" source="SECUNIA" adv="1">33799</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0256.html" source="REDHAT">RHSA-2009:0256</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9161" source="OVAL">oval:org.mitre.oval:def:9161</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00001.html" source="SUSE">SUSE-SA:2009:009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1"/>
        <vers num="0.10"/>
        <vers num="0.10.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.6.1"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.8"/>
        <vers num="0.9" edition="rc"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9_rc"/>
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="1.8"/>
        <vers num="2.0" edition="beta1"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0" edition="rc3"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="2.0_.1"/>
        <vers num="2.0_.10"/>
        <vers num="2.0_.4"/>
        <vers num="2.0_.5"/>
        <vers num="2.0_.6"/>
        <vers num="2.0_.7"/>
        <vers num="2.0_.9"/>
        <vers num="2.0_8"/>
        <vers num="3.0" edition="alpha"/>
        <vers num="3.0" edition="beta2"/>
        <vers num="3.0" edition="beta5"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers prev="1" num="3.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0356" published="2009-02-04" name="CVE-2009-0356" modified="2011-09-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the (1) about:plugins and (2) about:config URIs from .desktop files, which allows user-assisted remote attackers to bypass the Same Origin Policy and execute arbitrary code with chrome privileges via vectors involving the URL field in a Desktop Entry section of a .desktop file, related to representation of about: URIs as jar:file:// URIs.  NOTE: this issue exists because of an incomplete fix for CVE-2008-4582.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00240.html" source="FEDORA">FEDORA-2009-1399</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=460425" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=460425</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0313" source="VUPEN">ADV-2009-0313</ref>
      <ref url="http://www.securitytracker.com/id?1021666" source="SECTRACK">1021666</ref>
      <ref url="http://www.securityfocus.com/bid/33598" source="BID">33598</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-04.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-04.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:044" source="MANDRIVA">MDVSA-2009:044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm</ref>
      <ref url="http://secunia.com/advisories/33846" source="SECUNIA">33846</ref>
      <ref url="http://secunia.com/advisories/33841" source="SECUNIA">33841</ref>
      <ref url="http://secunia.com/advisories/33831" source="SECUNIA">33831</ref>
      <ref url="http://secunia.com/advisories/33809" source="SECUNIA">33809</ref>
      <ref url="http://secunia.com/advisories/33799" source="SECUNIA">33799</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0256.html" source="REDHAT">RHSA-2009:0256</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9922" source="OVAL">oval:org.mitre.oval:def:9922</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00001.html" source="SUSE">SUSE-SA:2009:009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1"/>
        <vers num="0.10"/>
        <vers num="0.10.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.6.1"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.8"/>
        <vers num="0.9" edition="rc"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9_rc"/>
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="1.8"/>
        <vers num="2.0" edition="beta1"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0" edition="rc3"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="2.0_.1"/>
        <vers num="2.0_.10"/>
        <vers num="2.0_.4"/>
        <vers num="2.0_.5"/>
        <vers num="2.0_.6"/>
        <vers num="2.0_.7"/>
        <vers num="2.0_.9"/>
        <vers num="2.0_8"/>
        <vers num="3.0" edition="alpha"/>
        <vers num="3.0" edition="beta2"/>
        <vers num="3.0" edition="beta5"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers prev="1" num="3.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0357" published="2009-02-04" name="CVE-2009-0357" modified="2011-09-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg01077.html" source="FEDORA">FEDORA-2009-3101</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00240.html" source="FEDORA">FEDORA-2009-1399</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=380418" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=380418</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0313" source="VUPEN">ADV-2009-0313</ref>
      <ref url="http://www.ubuntu.com/usn/usn-717-2" source="UBUNTU">USN-717-2</ref>
      <ref url="http://www.ubuntu.com/usn/usn-717-1" source="UBUNTU">USN-717-1</ref>
      <ref url="http://www.securitytracker.com/id?1021668" source="SECTRACK">1021668</ref>
      <ref url="http://www.securityfocus.com/bid/33598" source="BID">33598</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0257.html" source="REDHAT">RHSA-2009:0257</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-05.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-05.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:044" source="MANDRIVA">MDVSA-2009:044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.405420" source="SLACKWARE">SSA:2009-083-02</ref>
      <ref url="http://secunia.com/advisories/34527" source="SECUNIA">34527</ref>
      <ref url="http://secunia.com/advisories/34462" source="SECUNIA">34462</ref>
      <ref url="http://secunia.com/advisories/33869" source="SECUNIA">33869</ref>
      <ref url="http://secunia.com/advisories/33846" source="SECUNIA">33846</ref>
      <ref url="http://secunia.com/advisories/33841" source="SECUNIA">33841</ref>
      <ref url="http://secunia.com/advisories/33831" source="SECUNIA">33831</ref>
      <ref url="http://secunia.com/advisories/33816" source="SECUNIA">33816</ref>
      <ref url="http://secunia.com/advisories/33809" source="SECUNIA">33809</ref>
      <ref url="http://secunia.com/advisories/33808" source="SECUNIA">33808</ref>
      <ref url="http://secunia.com/advisories/33799" source="SECUNIA">33799</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0256.html" source="REDHAT">RHSA-2009:0256</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9459" source="OVAL">oval:org.mitre.oval:def:9459</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00001.html" source="SUSE">SUSE-SA:2009:009</ref>
      <ref url="http://ha.ckers.org/blog/20070511/bluehat-errata/" source="MISC">http://ha.ckers.org/blog/20070511/bluehat-errata/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.6.1"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="beta1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0" edition="rc3"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0" edition="alpha"/>
        <vers num="3.0" edition="beta2"/>
        <vers num="3.0" edition="beta5"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers prev="1" num="3.0.5"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers prev="1" num="1.1.13"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0358" published="2009-02-04" name="CVE-2009-0358" modified="2011-09-12" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="3.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.5" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">Mozilla Firefox 3.x before 3.0.6 does not properly implement the (1) no-store and (2) no-cache Cache-Control directives, which allows local users to obtain sensitive information by using the (a) back button or (b) history list of the victim's browser, as demonstrated by reading the response page of an https POST request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00240.html" source="FEDORA">FEDORA-2009-1399</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=441751" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=441751</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0313" source="VUPEN">ADV-2009-0313</ref>
      <ref url="http://www.ubuntu.com/usn/usn-717-1" source="UBUNTU">USN-717-1</ref>
      <ref url="http://www.securitytracker.com/id?1021667" source="SECTRACK">1021667</ref>
      <ref url="http://www.securityfocus.com/bid/33598" source="BID">33598</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-06.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-06.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:044" source="MANDRIVA">MDVSA-2009:044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm</ref>
      <ref url="http://secunia.com/advisories/33869" source="SECUNIA">33869</ref>
      <ref url="http://secunia.com/advisories/33846" source="SECUNIA">33846</ref>
      <ref url="http://secunia.com/advisories/33841" source="SECUNIA">33841</ref>
      <ref url="http://secunia.com/advisories/33831" source="SECUNIA">33831</ref>
      <ref url="http://secunia.com/advisories/33809" source="SECUNIA">33809</ref>
      <ref url="http://secunia.com/advisories/33799" source="SECUNIA">33799</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0256.html" source="REDHAT">RHSA-2009:0256</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10610" source="OVAL">oval:org.mitre.oval:def:10610</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00001.html" source="SUSE">SUSE-SA:2009:009</ref>
      <ref url="http://blogs.imeta.co.uk/JDeabill/archive/2008/07/14/303.aspx" source="MISC">http://blogs.imeta.co.uk/JDeabill/archive/2008/07/14/303.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0" edition="alpha"/>
        <vers num="3.0" edition="beta2"/>
        <vers num="3.0" edition="beta5"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0359" published="2009-02-17" name="CVE-2009-0359" modified="2009-03-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Samizdat before 0.6.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) message title or (2) user full name.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33768" source="BID" patch="1">33768</ref>
      <ref url="http://www.nongnu.org/samizdat/release-notes/samizdat-0.6.2.html" source="CONFIRM" patch="1" adv="1">http://www.nongnu.org/samizdat/release-notes/samizdat-0.6.2.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500961/100/0/threaded" source="BUGTRAQ">20090213 Cross-site scripting in Samizdat 0.6.1</ref>
      <ref url="http://www.mail-archive.com/debian-testing-security-announce@lists.debian.org/msg00171.html" source="MLIST">[debian-testing-security-announce] 20090211 Security update for Debian Testing - 2009-02-12</ref>
      <ref url="http://samizdat.nongnu.org/release-notes/samizdat-0.6.1-xss-escape-title.patch" source="CONFIRM" adv="1">http://samizdat.nongnu.org/release-notes/samizdat-0.6.1-xss-escape-title.patch</ref>
      <ref url="http://osvdb.org/52022" source="OSVDB">52022</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nongnu" name="samizdat">
        <vers prev="1" num="0.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0360" published="2009-02-13" name="CVE-2009-0360" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privileges by pointing an environment variable to a modified Kerberos configuration file, and then launching a PAM-based setuid application.</descript>
      <descript source="nvd">Per vendor advisory:
 http://www.eyrie.org/~eagle/software/pam-krb5/security/2009-02-11.html

"This advisory is only for my pam-krb5 module, as distributed from my web site and packaged by Debian, Ubuntu, and Gentoo."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0979" source="VUPEN">ADV-2009-0979</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0426" source="VUPEN">ADV-2009-0426</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0410" source="VUPEN">ADV-2009-0410</ref>
      <ref url="http://www.ubuntu.com/usn/USN-719-1" source="UBUNTU">USN-719-1</ref>
      <ref url="http://www.securityfocus.com/bid/33740" source="BID">33740</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500892/100/0/threaded" source="BUGTRAQ">20090211 pam-krb5 security advisory (3.12 and earlier)</ref>
      <ref url="http://www.eyrie.org/~eagle/software/pam-krb5/security/2009-02-11.html" source="MISC" adv="1">http://www.eyrie.org/~eagle/software/pam-krb5/security/2009-02-11.html</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1721" source="DEBIAN">DSA-1721</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-070.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-070.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-252767-1" source="SUNALERT">252767</ref>
      <ref url="http://securitytracker.com/id?1021711" source="SECTRACK">1021711</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200903-39.xml" source="GENTOO">GLSA-200903-39</ref>
      <ref url="http://secunia.com/advisories/34449" source="SECUNIA">34449</ref>
      <ref url="http://secunia.com/advisories/34260" source="SECUNIA">34260</ref>
      <ref url="http://secunia.com/advisories/33917" source="SECUNIA" adv="1">33917</ref>
      <ref url="http://secunia.com/advisories/33914" source="SECUNIA" adv="1">33914</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5732" source="OVAL">oval:org.mitre.oval:def:5732</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5669" source="OVAL">oval:org.mitre.oval:def:5669</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eyrie" name="pam-krb5">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.10"/>
        <vers num="3.11"/>
        <vers prev="1" num="3.12"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="3.6"/>
        <vers num="3.7"/>
        <vers num="3.8"/>
        <vers num="3.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0361" published="2009-02-13" name="CVE-2009-0361" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Russ Allbery pam-krb5 before 3.13, as used by libpam-heimdal, su in Solaris 10, and other software, does not properly handle calls to pam_setcred when running setuid, which allows local users to overwrite and change the ownership of arbitrary files by setting the KRB5CCNAME environment variable, and then launching a setuid application that performs certain pam_setcred operations.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0979" source="VUPEN">ADV-2009-0979</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0426" source="VUPEN">ADV-2009-0426</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0410" source="VUPEN">ADV-2009-0410</ref>
      <ref url="http://www.ubuntu.com/usn/USN-719-1" source="UBUNTU">USN-719-1</ref>
      <ref url="http://www.securityfocus.com/bid/33741" source="BID">33741</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500892/100/0/threaded" source="BUGTRAQ">20090211 pam-krb5 security advisory (3.12 and earlier)</ref>
      <ref url="http://www.eyrie.org/~eagle/software/pam-krb5/security/2009-02-11.html" source="MISC">http://www.eyrie.org/~eagle/software/pam-krb5/security/2009-02-11.html</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1722" source="DEBIAN">DSA-1722</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1721" source="DEBIAN">DSA-1721</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-070.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-070.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-252767-1" source="SUNALERT">252767</ref>
      <ref url="http://securitytracker.com/id?1021711" source="SECTRACK">1021711</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200903-39.xml" source="GENTOO">GLSA-200903-39</ref>
      <ref url="http://secunia.com/advisories/34449" source="SECUNIA">34449</ref>
      <ref url="http://secunia.com/advisories/34260" source="SECUNIA">34260</ref>
      <ref url="http://secunia.com/advisories/33918" source="SECUNIA" adv="1">33918</ref>
      <ref url="http://secunia.com/advisories/33917" source="SECUNIA" adv="1">33917</ref>
      <ref url="http://secunia.com/advisories/33914" source="SECUNIA" adv="1">33914</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5521" source="OVAL">oval:org.mitre.oval:def:5521</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5403" source="OVAL">oval:org.mitre.oval:def:5403</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eyrie" name="pam-krb5">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.10"/>
        <vers num="3.11"/>
        <vers prev="1" num="3.12"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="3.6"/>
        <vers num="3.7"/>
        <vers num="3.8"/>
        <vers num="3.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0362" published="2009-02-12" name="CVE-2009-0362" modified="2009-02-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">filter.d/wuftpd.conf in Fail2ban 0.8.3 uses an incorrect regular expression that allows remote attackers to cause a denial of service (forced authentication failures) via a crafted reverse-resolved DNS name (rhost) entry that contains a substring that is interpreted as an IP address, a different vulnerability than CVE-2007-4321.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33734" source="BID">33734</ref>
      <ref url="http://secunia.com/advisories/33890" source="SECUNIA" adv="1">33890</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=514163" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=514163</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fail2ban" name="fail2ban">
        <vers num="0.8.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0363" published="2009-02-17" name="CVE-2009-0363" modified="2010-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in (a) BarnOwl before 1.0.5 and (b) owl 2.1.11 allow remote attackers to execute arbitrary code via vectors involving (1) a crafted zcrypt message, related to zcrypt.c; (2) a reply command on a message with a Zephyr Cc: list, related to zwrite.c; and unspecified other use of the products.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugs.launchpad.net/ubuntu/+source/owl/+bug/329165" source="CONFIRM">https://bugs.launchpad.net/ubuntu/+source/owl/+bug/329165</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48824" source="XF">barnowl-owl-zcrypt-bo(48824)</ref>
      <ref url="http://www.mail-archive.com/debian-testing-security-announce@lists.debian.org/msg00173.html" source="MLIST">[debian-testing-security-announce] 20090213 Security update for Debian Testing - 2009-02-14</ref>
      <ref url="http://bugs.debian.org/515118" source="CONFIRM">http://bugs.debian.org/515118</ref>
      <ref url="http://barnowl.mit.edu/wiki/barnowl-1.0.5-announce" source="CONFIRM" adv="1">http://barnowl.mit.edu/wiki/barnowl-1.0.5-announce</ref>
      <ref url="http://barnowl.mit.edu/browser/ChangeLog" source="CONFIRM" adv="1">http://barnowl.mit.edu/browser/ChangeLog</ref>
    </refs>
    <vuln_soft>
      <prod vendor="barnowl" name="barnowl">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.2.1"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers prev="1" num="1.0.4.1"/>
      </prod>
      <prod vendor="ktools" name="owl">
        <vers num="2.1.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0364" published="2009-03-26" name="CVE-2009-0364" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the mini_calendar component in Citadel.org WebCit 7.22, and other versions before 7.39, allows remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34206" source="BID" patch="1">34206</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1752" source="DEBIAN">DSA-1752</ref>
      <ref url="http://www.citadel.org/doku.php/news:webcit.security.advisory.-.2009-march-23" source="CONFIRM" adv="1">http://www.citadel.org/doku.php/news:webcit.security.advisory.-.2009-march-23</ref>
      <ref url="http://secunia.com/advisories/34457" source="SECUNIA">34457</ref>
      <ref url="http://osvdb.org/52915" source="OSVDB">52915</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citadel" name="webcit">
        <vers num="7.02"/>
        <vers num="7.10"/>
        <vers num="7.11"/>
        <vers num="7.12"/>
        <vers num="7.22"/>
        <vers num="7.37"/>
        <vers prev="1" num="7.38"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0365" published="2009-03-04" name="CVE-2009-0365" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:N/A:N)" CVSS_score="4.6" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.1" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">nm-applet.conf in GNOME NetworkManager before 0.7.0.99 contains an incorrect deny setting, which allows local users to discover (1) network connection passwords and (2) pre-shared keys via calls to the GetSecrets method in the dbus request handler.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33966" source="BID" patch="1">33966</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=487752" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=487752</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=487722" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=487722</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49062" source="XF">networkmanager-dbus-info-disclosure(49062)</ref>
      <ref url="http://www.ubuntu.com/usn/USN-727-2" source="UBUNTU" adv="1">USN-727-2</ref>
      <ref url="http://www.ubuntu.com/usn/USN-727-1" source="UBUNTU" adv="1">USN-727-1</ref>
      <ref url="http://www.securitytracker.com/id?1021908" source="SECTRACK">1021908</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0362.html" source="REDHAT">RHSA-2009:0362</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0361.html" source="REDHAT">RHSA-2009:0361</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1955" source="DEBIAN">DSA-1955</ref>
      <ref url="http://svn.gnome.org/viewvc/network-manager-applet?view=revision&amp;revision=1207" source="CONFIRM">http://svn.gnome.org/viewvc/network-manager-applet?view=revision&amp;revision=1207</ref>
      <ref url="http://svn.gnome.org/viewvc/network-manager-applet/trunk/nm-applet.conf?r1=1133&amp;r2=1207&amp;pathrev=1207" source="CONFIRM">http://svn.gnome.org/viewvc/network-manager-applet/trunk/nm-applet.conf?r1=1133&amp;r2=1207&amp;pathrev=1207</ref>
      <ref url="http://securitytracker.com/id?1021911" source="SECTRACK">1021911</ref>
      <ref url="http://securitytracker.com/id?1021910" source="SECTRACK">1021910</ref>
      <ref url="http://secunia.com/advisories/34473" source="SECUNIA">34473</ref>
      <ref url="http://secunia.com/advisories/34177" source="SECUNIA">34177</ref>
      <ref url="http://secunia.com/advisories/34067" source="SECUNIA">34067</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10828" source="OVAL">oval:org.mitre.oval:def:10828</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html" source="SUSE">SUSE-SR:2009:009</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00003.html" source="SUSE">SUSE-SA:2009:013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="6.06" edition="-"/>
        <vers num="6.06" edition="-:lts"/>
        <vers num="7.10"/>
        <vers num="8.04" edition="-"/>
        <vers num="8.04" edition="-:lts"/>
        <vers num="8.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0366" published="2009-03-12" name="CVE-2009-0366" modified="2009-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The uncompress_buffer function in src/server/simple_wml.cpp in Wesnoth before r33069 allows remote attackers to cause a denial of service via a large compressed WML document.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://gna.org/bugs/index.php?13037" source="CONFIRM">https://gna.org/bugs/index.php?13037</ref>
      <ref url="http://www.securityfocus.com/bid/34085" source="BID">34085</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1737" source="DEBIAN">DSA-1737</ref>
      <ref url="http://svn.gna.org/viewcvs/wesnoth/trunk/src/server/simple_wml.cpp?rev=33069&amp;view=log" source="CONFIRM">http://svn.gna.org/viewcvs/wesnoth/trunk/src/server/simple_wml.cpp?rev=33069&amp;view=log</ref>
      <ref url="http://svn.gna.org/viewcvs/wesnoth/trunk/src/server/simple_wml.cpp?rev=33069&amp;r1=32990&amp;r2=33069" source="CONFIRM">http://svn.gna.org/viewcvs/wesnoth/trunk/src/server/simple_wml.cpp?rev=33069&amp;r1=32990&amp;r2=33069</ref>
      <ref url="http://secunia.com/advisories/34253" source="SECUNIA">34253</ref>
      <ref url="http://secunia.com/advisories/34236" source="SECUNIA">34236</ref>
      <ref url="http://packages.debian.org/changelogs/pool/main/w/wesnoth/wesnoth_1.5.12-1/changelog" source="CONFIRM">http://packages.debian.org/changelogs/pool/main/w/wesnoth/wesnoth_1.5.12-1/changelog</ref>
      <ref url="http://packages.debian.org/changelogs/pool/main/w/wesnoth/wesnoth_1.4.7-4/changelog" source="CONFIRM">http://packages.debian.org/changelogs/pool/main/w/wesnoth/wesnoth_1.4.7-4/changelog</ref>
      <ref url="http://osvdb.org/52672" source="OSVDB">52672</ref>
      <ref url="http://launchpad.net/bugs/cve/2009-0366" source="CONFIRM">http://launchpad.net/bugs/cve/2009-0366</ref>
      <ref url="http://launchpad.net/bugs/336396" source="CONFIRM">http://launchpad.net/bugs/336396</ref>
      <ref url="http://launchpad.net/bugs/335089" source="CONFIRM">http://launchpad.net/bugs/335089</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wesnoth" name="wesnoth">
        <vers num="1.0" edition="rc"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.2.8"/>
        <vers num="1.3.10"/>
        <vers num="1.3.11"/>
        <vers num="1.3.12"/>
        <vers num="1.3.13"/>
        <vers num="1.3.14"/>
        <vers num="1.3.15"/>
        <vers num="1.3.16"/>
        <vers num="1.3.17"/>
        <vers num="1.3.18"/>
        <vers num="1.3.19"/>
        <vers num="1.3.8"/>
        <vers num="1.3.9"/>
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.4.4"/>
        <vers num="1.4.5"/>
        <vers num="1.4.6"/>
        <vers num="1.4.7"/>
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.10"/>
        <vers prev="1" num="1.5.11"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="1.5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0367" published="2009-03-04" name="CVE-2009-0367" modified="2010-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute arbitrary code by using a whitelisted module that imports an unsafe module, then using a hierarchical module name to access the unsafe module through the whitelisted module.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.wesnoth.org/forum/viewtopic.php?t=24340" source="CONFIRM" patch="1" adv="1">http://www.wesnoth.org/forum/viewtopic.php?t=24340</ref>
      <ref url="http://www.wesnoth.org/forum/viewtopic.php?t=24247" source="CONFIRM" patch="1" adv="1">http://www.wesnoth.org/forum/viewtopic.php?t=24247</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0595" source="VUPEN" patch="1" adv="1">ADV-2009-0595</ref>
      <ref url="https://gna.org/bugs/index.php?13048" source="CONFIRM">https://gna.org/bugs/index.php?13048</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49058" source="XF">wesnoth-pythonai-code-execution(49058)</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1737" source="DEBIAN">DSA-1737</ref>
      <ref url="http://secunia.com/advisories/34236" source="SECUNIA">34236</ref>
      <ref url="http://secunia.com/advisories/34058" source="SECUNIA" adv="1">34058</ref>
      <ref url="http://packages.debian.org/changelogs/pool/main/w/wesnoth/wesnoth_1.5.12-1/changelog" source="CONFIRM">http://packages.debian.org/changelogs/pool/main/w/wesnoth/wesnoth_1.5.12-1/changelog</ref>
      <ref url="http://packages.debian.org/changelogs/pool/main/w/wesnoth/wesnoth_1.4.7-4/changelog" source="CONFIRM">http://packages.debian.org/changelogs/pool/main/w/wesnoth/wesnoth_1.4.7-4/changelog</ref>
      <ref url="http://launchpad.net/bugs/cve/2009-0367" source="CONFIRM">http://launchpad.net/bugs/cve/2009-0367</ref>
      <ref url="http://launchpad.net/bugs/336396" source="CONFIRM">http://launchpad.net/bugs/336396</ref>
      <ref url="http://launchpad.net/bugs/335089" source="CONFIRM">http://launchpad.net/bugs/335089</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wesnoth" name="wesnoth">
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.4.4"/>
        <vers num="1.4.5"/>
        <vers num="1.4.6"/>
        <vers num="1.4.7"/>
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.10"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="1.5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0368" published="2009-03-02" name="CVE-2009-0368" modified="2010-04-27" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data objects via a (1) low level APDU command or (2) debugging tool, as demonstrated by reading the 4601 or 4701 file with the opensc-explorer or opensc-tool program.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33922" source="BID" patch="1">33922</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/02/26/1" source="MLIST" patch="1">[oss-security] 20090226 OpenSC Security Advisory</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00686.html" source="FEDORA">FEDORA-2009-2267</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00673.html" source="FEDORA">FEDORA-2009-2266</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48958" source="XF">opensc-pkcs-unauth-access(48958)</ref>
      <ref url="http://www.opensc-project.org/pipermail/opensc-announce/2009-February/000023.html" source="MLIST" adv="1">[opensc-announce] 20090226 OpenSC Security Advisory</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1734" source="DEBIAN">DSA-1734</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200908-01.xml" source="GENTOO">GLSA-200908-01</ref>
      <ref url="http://secunia.com/advisories/36074" source="SECUNIA">36074</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA">35065</ref>
      <ref url="http://secunia.com/advisories/34377" source="SECUNIA">34377</ref>
      <ref url="http://secunia.com/advisories/34362" source="SECUNIA">34362</ref>
      <ref url="http://secunia.com/advisories/34120" source="SECUNIA">34120</ref>
      <ref url="http://secunia.com/advisories/34052" source="SECUNIA" adv="1">34052</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opensc-project" name="opensc">
        <vers num="0.10.0"/>
        <vers num="0.10.1"/>
        <vers num="0.11.0"/>
        <vers num="0.11.1"/>
        <vers num="0.11.2"/>
        <vers num="0.11.3" edition="pre3"/>
        <vers num="0.11.4"/>
        <vers num="0.11.5"/>
        <vers prev="1" num="0.11.6"/>
        <vers num="0.3.2"/>
        <vers num="0.3.5"/>
        <vers num="0.4.0"/>
        <vers num="0.5.0"/>
        <vers num="0.6.0"/>
        <vers num="0.6.1"/>
        <vers num="0.7.0"/>
        <vers num="0.8"/>
        <vers num="0.8.0"/>
        <vers num="0.8.0.0"/>
        <vers num="0.8.1"/>
        <vers num="0.9"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
        <vers num="0.9.7" edition="b"/>
        <vers num="0.9.7" edition="d"/>
        <vers num="0.9.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0369" published="2009-01-30" name="CVE-2009-0369" modified="2009-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 7 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Clickjacking" vulnerability.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48542" source="XF">ie-onclickaction-click-hijacking(48542)</ref>
      <ref url="http://www.milw0rm.com/exploits/7912" source="MILW0RM">7912</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0370" published="2009-01-30" name="CVE-2009-0370" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in IBM AIX 5.2.0 through 6.1.2 allow local users to append data to arbitrary files, related to (1) rmsock and (2) rmsock64 not creating "secure log files."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33522" source="BID" patch="1">33522</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ42788" source="AIXAPAR" patch="1">IZ42788</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ42787" source="AIXAPAR" patch="1">IZ42787</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ42786" source="AIXAPAR" patch="1">IZ42786</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ42785" source="AIXAPAR" patch="1">IZ42785</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ41599" source="AIXAPAR" patch="1">IZ41599</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ41510" source="AIXAPAR" patch="1">IZ41510</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ40386" source="AIXAPAR" patch="1">IZ40386</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ41593" source="AIXAPAR">IZ41593</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6028" source="OVAL">oval:org.mitre.oval:def:6028</ref>
      <ref url="http://aix.software.ibm.com/aix/efixes/security/rmsock_advisory.asc" source="CONFIRM">http://aix.software.ibm.com/aix/efixes/security/rmsock_advisory.asc</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.2"/>
        <vers num="5.2.2"/>
        <vers num="5.2_l"/>
        <vers num="5.3"/>
        <vers num="5.3.7"/>
        <vers num="5.3.8"/>
        <vers num="5.3.9"/>
        <vers num="5.3_l"/>
        <vers num="6.1"/>
        <vers num="6.1.1"/>
        <vers num="6.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0371" published="2009-01-30" name="CVE-2009-0371" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in post.php in SiteXS CMS 0.1.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the type parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48236" source="XF">sitexs-type-file-include(48236)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0247" source="VUPEN">ADV-2009-0247</ref>
      <ref url="http://www.securityfocus.com/bid/33457" source="BID">33457</ref>
      <ref url="http://www.milw0rm.com/exploits/7879" source="MILW0RM">7879</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sitexs_cms" name="sitexs_cms">
        <vers num="0.1" edition="pre-alpha"/>
        <vers prev="1" num="0.1.1" edition="pre-alpha"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0372" published="2009-01-30" name="CVE-2009-0372" modified="2009-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in index.php in Miltenovik Manojlo MemHT Portal 4.0.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension and an image content type via a users editProfile action, then accessing this file via a direct request to the file in images/avatar/uploaded/.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33424" source="BID" patch="1">33424</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48199" source="XF">memht-avatar-file-upload(48199)</ref>
      <ref url="http://www.milw0rm.com/exploits/7859" source="MILW0RM">7859</ref>
      <ref url="http://secunia.com/advisories/33626" source="SECUNIA" adv="1">33626</ref>
    </refs>
    <vuln_soft>
      <prod vendor="memht" name="memht_portal">
        <vers num="1.0" edition="final"/>
        <vers num="1.5" edition="full"/>
        <vers num="1.5" edition="update"/>
        <vers num="2.0" edition="full"/>
        <vers num="2.0" edition="update"/>
        <vers num="2.5" edition="full"/>
        <vers num="2.5" edition="update"/>
        <vers num="2.9" edition="full"/>
        <vers num="2.9" edition="update"/>
        <vers num="3.0" edition="full"/>
        <vers num="3.0" edition="update"/>
        <vers num="3.1" edition="full"/>
        <vers num="3.1" edition="update"/>
        <vers num="3.2" edition="update"/>
        <vers num="3.3" edition="full"/>
        <vers num="3.3" edition="update"/>
        <vers num="3.4" edition="full"/>
        <vers num="3.4" edition="update"/>
        <vers num="3.4.5" edition="full"/>
        <vers num="3.4.5" edition="update"/>
        <vers num="3.5.0" edition="full"/>
        <vers num="3.6.0"/>
        <vers num="3.6.5"/>
        <vers num="3.7.0"/>
        <vers num="3.7.5"/>
        <vers num="3.8.0"/>
        <vers num="3.8.1"/>
        <vers num="3.8.5"/>
        <vers num="3.9.0"/>
        <vers prev="1" num="4.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0373" published="2009-01-30" name="CVE-2009-0373" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the ElearningForce Flash Magazine Deluxe (com_flashmagazinedeluxe) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mag_id parameter in a magazine action to index.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48226" source="XF">flashmagazine-index-sql-injection(48226)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0249" source="VUPEN">ADV-2009-0249</ref>
      <ref url="http://www.securityfocus.com/bid/33455" source="BID">33455</ref>
      <ref url="http://www.milw0rm.com/exploits/7881" source="MILW0RM">7881</ref>
      <ref url="http://secunia.com/advisories/33646" source="SECUNIA" adv="1">33646</ref>
    </refs>
    <vuln_soft>
      <prod vendor="elearningforce" name="flash_magazine_deluxe">
        <vers num="_nil_"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0374" published="2009-01-30" name="CVE-2009-0374" modified="2009-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">** DISPUTED **  Google Chrome 1.0.154.43 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Clickjacking" vulnerability.  NOTE: a third party disputes the relevance of this issue, stating that "every sufficiently featured browser is and likely will remain susceptible to the behavior known as clickjacking," and adding that the exploit code "is not a valid demonstration of the issue."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500533/100/0/threaded" source="BUGTRAQ">20090128 Re: Advisory: Google Chrome 1.0.154.43 ClickJacking Vulnerability.</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500499/100/0/threaded" source="BUGTRAQ">20090128 Advisory: Google Chrome 1.0.154.43 ClickJacking Vulnerability.</ref>
      <ref url="http://www.secniche.org/gcr_clkj/" source="MISC">http://www.secniche.org/gcr_clkj/</ref>
      <ref url="http://www.milw0rm.com/exploits/7903" source="MILW0RM">7903</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="1.0.154.43"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0375" published="2009-02-08" name="CVE-2009-0375" modified="2010-01-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in a DLL file in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to execute arbitrary code via a crafted Internet Video Recording (IVR) file with a filename length field containing a large integer, which triggers overwrite of an arbitrary memory location with a 0x00 byte value, related to use of RealPlayer through a Windows Explorer plugin.</descript>
      <descript source="nvd">Per http://www.fortiguardcenter.com/advisory/FGA-2009-04.html:

"It should be noted that the victim does not necessarily have to open the malicious file for exploitation to occur: the vulnerabilities lie in a DLL that is also used as a plugin for the Windows Explorer shell. A successful attack could take place by merely previewing the IVR file through Windows Explorer. "</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48567" source="XF">realplayer-ivr-bo(48567)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0178" source="VUPEN">ADV-2010-0178</ref>
      <ref url="http://www.securityfocus.com/bid/33652" source="BID">33652</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500722/100/0/threaded" source="BUGTRAQ">20090206 RealNetworks RealPlayer IVR File Processing Multiple Code Execute Vulnerabilities</ref>
      <ref url="http://www.fortiguardcenter.com/advisory/FGA-2009-04.html" source="MISC">http://www.fortiguardcenter.com/advisory/FGA-2009-04.html</ref>
      <ref url="http://service.real.com/realplayer/security/01192010_player/en/" source="CONFIRM">http://service.real.com/realplayer/security/01192010_player/en/</ref>
      <ref url="http://secunia.com/advisories/38218" source="SECUNIA">38218</ref>
      <ref url="http://secunia.com/advisories/33810" source="SECUNIA">33810</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0376" published="2009-02-08" name="CVE-2009-0376" modified="2010-01-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in a DLL file in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to execute arbitrary code via a crafted Internet Video Recording (IVR) file with a modified field that controls an unspecified structure length and triggers heap corruption, related to use of RealPlayer through a Windows Explorer plugin.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48568" source="XF">realplayer-ivr-code-execution(48568)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-009/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-009/</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0178" source="VUPEN">ADV-2010-0178</ref>
      <ref url="http://www.securityfocus.com/bid/33652" source="BID">33652</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509097/100/0/threaded" source="BUGTRAQ">20100121 ZDI-10-009: RealNetworks RealPlayer IVR Format Remote Code Execution Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500722/100/0/threaded" source="BUGTRAQ">20090206 RealNetworks RealPlayer IVR File Processing Multiple Code Execute Vulnerabilities</ref>
      <ref url="http://www.fortiguardcenter.com/advisory/FGA-2009-04.html" source="MISC">http://www.fortiguardcenter.com/advisory/FGA-2009-04.html</ref>
      <ref url="http://service.real.com/realplayer/security/01192010_player/en/" source="CONFIRM">http://service.real.com/realplayer/security/01192010_player/en/</ref>
      <ref url="http://secunia.com/advisories/38218" source="SECUNIA">38218</ref>
      <ref url="http://secunia.com/advisories/33810" source="SECUNIA">33810</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0377" published="2009-02-02" name="CVE-2009-0377" modified="2009-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mpid parameter in a sign action to index.php, a different vector than CVE-2008-3132.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33391" source="BID">33391</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500250/100/0/threaded" source="BUGTRAQ">20090121 Joomla component beamospetition 1.0.12 Sql Injection</ref>
      <ref url="http://www.milw0rm.com/exploits/7847" source="MILW0RM">7847</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="com_beamospetition">
        <vers num="1.0.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0378" published="2009-02-02" name="CVE-2009-0378" modified="2009-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the pet parameter in a sign action.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33391" source="BID">33391</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500250/100/0/threaded" source="BUGTRAQ">20090121 Joomla component beamospetition 1.0.12 Sql Injection</ref>
      <ref url="http://www.milw0rm.com/exploits/7847" source="MILW0RM">7847</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="com_beamospetition">
        <vers num="1.0.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0379" published="2009-02-02" name="CVE-2009-0379" modified="2009-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Prince Clan Chess Club (com_pcchess) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the game_id parameter in a showgame action to index.php, a different vector than CVE-2008-0761.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48144" source="XF">joomla-pcchess-gameid-sql-injection(48144)</ref>
      <ref url="http://www.securityfocus.com/bid/33394" source="BID">33394</ref>
      <ref url="http://www.milw0rm.com/exploits/7846" source="MILW0RM">7846</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="com_pcchess">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0380" published="2009-02-02" name="CVE-2009-0380" modified="2009-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  SQL injection vulnerability in the Sigsiu Online Business Index 2 (SOBI2, com_sobi2) RC 2.8.2 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the bid parameter in a showbiz action to index.php, a different vector than CVE-2008-0607.  NOTE: CVE disputes this issue, since neither "showbiz" nor "bid" appears in the source code for SOBI2.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48131" source="XF">sobi2-bid-sql-injection(48131)</ref>
      <ref url="http://www.securityfocus.com/bid/33378" source="BID">33378</ref>
      <ref url="http://www.milw0rm.com/exploits/7841" source="MILW0RM">7841</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2009-January/002136.html" source="VIM">20090130 SOBI2 showbiz SQL injection - false, or site-specific</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sigsiu.net" name="sobi2">
        <vers num="2.8.2" edition="rc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0381" published="2009-02-02" name="CVE-2009-0381" modified="2009-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the BazaarBuilder Ecommerce Shopping Cart (com_prod) 5.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in a products action to index.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48141" source="XF">bazaarbuilder-index-sql-injection(48141)</ref>
      <ref url="http://www.securityfocus.com/bid/33380" source="BID">33380</ref>
      <ref url="http://www.milw0rm.com/exploits/7840" source="MILW0RM">7840</ref>
      <ref url="http://secunia.com/advisories/33612" source="SECUNIA" adv="1">33612</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bazaarbuilder" name="ecommerce_shopping_cart">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0382" published="2009-02-02" name="CVE-2009-0382" modified="2009-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Internationalization (i18n) Translation 5.x before 5.x-2.5, a module for Drupal, allows remote attackers with "translate node" permissions to bypass intended access restrictions and read unpublished nodes via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://drupal.org/node/358958" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/358958</ref>
      <ref url="http://www.securityfocus.com/bid/33283" source="BID">33283</ref>
      <ref url="http://secunia.com/advisories/33549" source="SECUNIA" adv="1">33549</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="internationalization">
        <vers num="5.x-1.1"/>
        <vers prev="1" num="5.x-2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0383" published="2009-02-02" name="CVE-2009-0383" modified="2009-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">delete.php in Max.Blog 1.0.6 does not properly restrict access, which allows remote attackers to delete arbitrary blog posts via a direct request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.mzbservices.com/show_post.php?id=72" source="CONFIRM" patch="1" adv="1">http://www.mzbservices.com/show_post.php?id=72</ref>
      <ref url="http://secunia.com/advisories/33590" source="SECUNIA" patch="1" adv="1">33590</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48125" source="XF">maxblog-delete-security-bypass(48125)</ref>
      <ref url="http://www.securityfocus.com/bid/33368" source="BID">33368</ref>
      <ref url="http://www.milw0rm.com/exploits/7835" source="MILW0RM">7835</ref>
      <ref url="http://osvdb.org/51482" source="OSVDB">51482</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mzbservices" name="max.blog">
        <vers num="1.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0384" published="2009-02-02" name="CVE-2009-0384" modified="2009-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in autor.php in OwnRS CMS 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/7849" source="MILW0RM">7849</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adam_tomecek" name="ownrs">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0385" published="2009-02-02" name="CVE-2009-0385" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track value, which triggers a NULL pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00215.html" source="FEDORA">FEDORA-2009-3433</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00210.html" source="FEDORA">FEDORA-2009-3428</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48330" source="XF">ffmpeg-fourxmreadheader-code-execution(48330)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0277" source="VUPEN">ADV-2009-0277</ref>
      <ref url="http://www.ubuntu.com/usn/USN-734-1" source="UBUNTU">USN-734-1</ref>
      <ref url="http://www.trapkit.de/advisories/TKADV2009-004.txt" source="MISC">http://www.trapkit.de/advisories/TKADV2009-004.txt</ref>
      <ref url="http://www.securityfocus.com/bid/33502" source="BID">33502</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500514/100/0/threaded" source="BUGTRAQ">20090128 [TKADV2009-004] FFmpeg Type Conversion Vulnerability</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:297" source="MANDRIVA">MDVSA-2009:297</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1782" source="DEBIAN">DSA-1782</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1781" source="DEBIAN">DSA-1781</ref>
      <ref url="http://svn.mplayerhq.hu/ffmpeg?view=rev&amp;revision=16846" source="CONFIRM">http://svn.mplayerhq.hu/ffmpeg?view=rev&amp;revision=16846</ref>
      <ref url="http://svn.mplayerhq.hu/ffmpeg/trunk/libavformat/4xm.c?r1=16838&amp;r2=16846&amp;pathrev=16846" source="CONFIRM">http://svn.mplayerhq.hu/ffmpeg/trunk/libavformat/4xm.c?r1=16838&amp;r2=16846&amp;pathrev=16846</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200903-33.xml" source="GENTOO">GLSA-200903-33</ref>
      <ref url="http://secunia.com/advisories/34905" source="SECUNIA">34905</ref>
      <ref url="http://secunia.com/advisories/34845" source="SECUNIA">34845</ref>
      <ref url="http://secunia.com/advisories/34712" source="SECUNIA">34712</ref>
      <ref url="http://secunia.com/advisories/34385" source="SECUNIA">34385</ref>
      <ref url="http://secunia.com/advisories/34296" source="SECUNIA">34296</ref>
      <ref url="http://secunia.com/advisories/33711" source="SECUNIA" adv="1">33711</ref>
      <ref url="http://osvdb.org/51643" source="OSVDB">51643</ref>
      <ref url="http://git.ffmpeg.org/?p=ffmpeg;a=commitdiff;h=72e715fb798f2cb79fd24a6d2eaeafb7c6eeda17" source="CONFIRM">http://git.ffmpeg.org/?p=ffmpeg;a=commitdiff;h=72e715fb798f2cb79fd24a6d2eaeafb7c6eeda17</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ffmpeg" name="ffmpeg">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0386" published="2009-02-02" name="CVE-2009-0386" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11 might allow remote attackers to execute arbitrary code via crafted Composition Time To Sample (ctts) atom data in a malformed QuickTime media .mov file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33405" source="BID" patch="1">33405</ref>
      <ref url="http://gstreamer.freedesktop.org/releases/gst-plugins-good/0.10.12.html" source="CONFIRM" patch="1" adv="1">http://gstreamer.freedesktop.org/releases/gst-plugins-good/0.10.12.html</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=481267" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=481267</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0225" source="VUPEN">ADV-2009-0225</ref>
      <ref url="http://www.ubuntu.com/usn/USN-736-1" source="UBUNTU">USN-736-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500317/100/0/threaded" source="BUGTRAQ">20090122 [TKADV2009-003] GStreamer Heap Overflow and Array Index out of Bounds Vulnerabilities</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0271.html" source="REDHAT">RHSA-2009:0271</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/29/3" source="MLIST">[oss-security] 20090129 CVE Request -- (sort of urgent) gstreamer-plugins-good (repost) (more details about affected versions -- final version)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:035" source="MANDRIVA">MDVSA-2009:035</ref>
      <ref url="http://trapkit.de/advisories/TKADV2009-003.txt" source="MISC">http://trapkit.de/advisories/TKADV2009-003.txt</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-11.xml" source="GENTOO">GLSA-200907-11</ref>
      <ref url="http://secunia.com/advisories/35777" source="SECUNIA">35777</ref>
      <ref url="http://secunia.com/advisories/34336" source="SECUNIA">34336</ref>
      <ref url="http://secunia.com/advisories/33815" source="SECUNIA">33815</ref>
      <ref url="http://secunia.com/advisories/33650" source="SECUNIA" adv="1">33650</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10306" source="OVAL">oval:org.mitre.oval:def:10306</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html" source="SUSE">SUSE-SR:2009:005</ref>
      <ref url="http://cgit.freedesktop.org/gstreamer/gst-plugins-good/commit/?id=bdc20b9baf13564d9a061343416395f8f9a92b53" source="CONFIRM">http://cgit.freedesktop.org/gstreamer/gst-plugins-good/commit/?id=bdc20b9baf13564d9a061343416395f8f9a92b53</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gstreamer" name="good_plug-ins">
        <vers num="0.10.10"/>
        <vers num="0.10.11"/>
        <vers num="0.10.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0387" published="2009-02-02" name="CVE-2009-0387" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Array index error in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted Sync Sample (aka stss) atom data in a malformed QuickTime media .mov file, related to "mark keyframes."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://gstreamer.freedesktop.org/releases/gst-plugins-good/0.10.12.html" source="CONFIRM" patch="1" adv="1">http://gstreamer.freedesktop.org/releases/gst-plugins-good/0.10.12.html</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=481267" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=481267</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0225" source="VUPEN">ADV-2009-0225</ref>
      <ref url="http://www.ubuntu.com/usn/USN-736-1" source="UBUNTU">USN-736-1</ref>
      <ref url="http://www.securityfocus.com/bid/33405" source="BID">33405</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500317/100/0/threaded" source="BUGTRAQ">20090122 [TKADV2009-003] GStreamer Heap Overflow and Array Index out of Bounds Vulnerabilities</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0271.html" source="REDHAT">RHSA-2009:0271</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/29/3" source="MLIST">[oss-security] 20090129 CVE Request -- (sort of urgent) gstreamer-plugins-good (repost) (more details about affected versions -- final version)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:035" source="MANDRIVA">MDVSA-2009:035</ref>
      <ref url="http://trapkit.de/advisories/TKADV2009-003.txt" source="MISC">http://trapkit.de/advisories/TKADV2009-003.txt</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-11.xml" source="GENTOO">GLSA-200907-11</ref>
      <ref url="http://secunia.com/advisories/35777" source="SECUNIA">35777</ref>
      <ref url="http://secunia.com/advisories/34336" source="SECUNIA">34336</ref>
      <ref url="http://secunia.com/advisories/33815" source="SECUNIA">33815</ref>
      <ref url="http://secunia.com/advisories/33650" source="SECUNIA" adv="1">33650</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10611" source="OVAL">oval:org.mitre.oval:def:10611</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html" source="SUSE">SUSE-SR:2009:005</ref>
      <ref url="http://cgit.freedesktop.org/gstreamer/gst-plugins-good/commit/?id=bdc20b9baf13564d9a061343416395f8f9a92b53" source="CONFIRM">http://cgit.freedesktop.org/gstreamer/gst-plugins-good/commit/?id=bdc20b9baf13564d9a061343416395f8f9a92b53</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gstreamer" name="good_plug-ins">
        <vers num="0.10.10"/>
        <vers num="0.10.11"/>
        <vers num="0.10.9"/>
      </prod>
      <prod vendor="gstreamer" name="plug-ins">
        <vers num="0.8.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0388" published="2009-02-04" name="CVE-2009-0388" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code via a large length value in a message, related to the (a) ClientConnection::CheckBufferSize and (b) ClientConnection::CheckFileZipBufferSize functions in ClientConnection.cpp.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33568" source="BID" patch="1">33568</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0322" source="VUPEN">ADV-2009-0322</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0321" source="VUPEN">ADV-2009-0321</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500632/100/0/threaded" source="BUGTRAQ">20090203 CORE-2008-1009 - VNC Multiple Integer Overflows</ref>
      <ref url="http://www.milw0rm.com/exploits/8024" source="MILW0RM">8024</ref>
      <ref url="http://www.milw0rm.com/exploits/7990" source="MILW0RM">7990</ref>
      <ref url="http://www.coresecurity.com/content/vnc-integer-overflows" source="MISC">http://www.coresecurity.com/content/vnc-integer-overflows</ref>
      <ref url="http://vnc-tight.svn.sourceforge.net/viewvc/vnc-tight?view=rev&amp;revision=3564" source="CONFIRM">http://vnc-tight.svn.sourceforge.net/viewvc/vnc-tight?view=rev&amp;revision=3564</ref>
      <ref url="http://secunia.com/advisories/33807" source="SECUNIA">33807</ref>
      <ref url="http://forum.ultravnc.info/viewtopic.php?t=14654" source="CONFIRM">http://forum.ultravnc.info/viewtopic.php?t=14654</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tightvnc" name="tightvnc">
        <vers num="1.3.9"/>
      </prod>
      <prod vendor="ultravnc" name="ultravnc">
        <vers num="1.0.2"/>
        <vers num="1.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0389" published="2009-02-02" name="CVE-2009-0389" modified="2009-02-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple insecure method vulnerabilities in the Web On Windows (WOW) ActiveX control in WOW ActiveX 2 allow remote attackers to (1) create and overwrite arbitrary files via the WriteIniFileString method, (2) execute arbitrary programs via the ShellExecute method, (3) read from the registry via unspecified vectors, and (4) write to the registry via unspecified vectors.  NOTE: vectors 1 and 2 can be used together to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <se